PT-2019-17045 · Oracle+2 · Oracle+3

Published

2019-07-01

·

Updated

2022-12-03

·

CVE-2019-4357

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0 through 10.1.3
Description The issue allows execution of arbitrary code on the system when performing a redirected restore operation that specifies a target path, particularly when protecting Oracle, DB2, or MongoDB databases.
Recommendations For versions 10.1.0 through 10.1.3, consider restricting access to the restore operation until a fix is available, and avoid specifying target paths that could be exploited to execute arbitrary code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2019-4357

Affected Products

Db2
Ibm Spectrum Protect Plus
Mongodb
Oracle