PT-2019-17120 · Ibm · Db2 Mirror For I+1
Published
2019-08-29
·
Updated
2022-12-02
·
CVE-2019-4536
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IBM i version 7.4
Description
The issue arises when a Restore User Profile (RSTUSRPRF) is performed on a system configured with Db2 Mirror for i, potentially resulting in user profiles having elevated privileges due to incorrect processing during the restoration of multiple user profiles. A user with restore privileges could exploit this to obtain elevated privileges on the restored system.
Recommendations
For IBM i version 7.4, ensure that user profiles are properly validated after a restore operation to prevent elevated privileges, and consider restricting access to the restore function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Db2 Mirror For I
Ibm I