First published: Fri Aug 23 2019(Updated: )
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4536 is considered a high severity vulnerability due to the potential for unauthorized privilege escalation.
To remediate CVE-2019-4536, it is recommended to review user profiles for elevated privileges and apply the latest patches from IBM.
CVE-2019-4536 affects IBM i version 7.4 users who have restored user profiles on systems with Db2 Mirror for i configured.
An attacker with restore privileges could exploit CVE-2019-4536 to gain unauthorized access and elevated privileges on the system.
While a specific workaround for CVE-2019-4536 is not documented, users are advised to restrict access to restore privileges to mitigate risk.