First published: Mon Nov 11 2019(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | <=10.1.0-10.1.4 | |
IBM Spectrum Protect Plus | >=10.1.0<=10.1.4 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4652 is considered a medium severity vulnerability due to the potential for unauthorized access to sensitive information.
To fix CVE-2019-4652, you should upgrade IBM Spectrum Protect Plus to version 10.1.5 or later, where the insecure file permission issue is resolved.
CVE-2019-4652 allows local users to exploit insecure file permissions on restored files and directories, potentially leading to unauthorized actions.
CVE-2019-4652 affects IBM Spectrum Protect Plus versions 10.1.0 through 10.1.4.
A potential workaround for CVE-2019-4652 is to manually adjust the file permissions on restored files to restrict access until an upgrade is possible.