PT-2019-16984 · Veritas+2 · Vxfs+2
Published
2019-07-22
·
Updated
2022-12-02
·
CVE-2019-4236
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Protect version 7.1
Description
The issue affects the backup or archive operation of HP-UX VxFS objects. If an object has more than twelve Access Control List (ACL) entries, the IBM Spectrum Protect client silently skips these entries during backup or archive operations. This could allow a local attacker to restore or retrieve the object with incorrect ACL entries, potentially leading to unauthorized access.
Recommendations
For IBM Spectrum Protect version 7.1, consider restricting access to sensitive objects until a fix is available to prevent unauthorized restoration or retrieval with incorrect ACL entries. As a temporary workaround, limit the number of ACL entries associated with each object to twelve or fewer to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hp-Ux
Ibm Spectrum Protect
Vxfs