CVE-2019-4652: High severity ibm storage protect plus vulnerability
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.
Other sources
Incorrect permissions on restored files and directories on Windows using IBM Spectrum Protect Plus.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4652?
CVE-2019-4652 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2019-4652?
To fix CVE-2019-4652, you should upgrade IBM Spectrum Protect Plus to version 10.1.5 or later, where the insecure file permission issue is resolved.
What impact does CVE-2019-4652 have on IBM Spectrum Protect Plus?
CVE-2019-4652 allows local users to exploit insecure file permissions on restored files and directories, potentially leading to unauthorized actions.
Which versions of IBM Spectrum Protect Plus are affected by CVE-2019-4652?
CVE-2019-4652 affects IBM Spectrum Protect Plus versions 10.1.0 through 10.1.4.
Is there a workaround for CVE-2019-4652 if I cannot upgrade?
A potential workaround for CVE-2019-4652 is to manually adjust the file permissions on restored files to restrict access until an upgrade is possible.