PT-2019-17120 · Ibm · Db2 Mirror For I+1

Published

2019-08-29

·

Updated

2022-12-02

·

CVE-2019-4536

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM i version 7.4
Description The issue arises when a Restore User Profile (RSTUSRPRF) is performed on a system configured with Db2 Mirror for i, potentially resulting in user profiles having elevated privileges due to incorrect processing during the restoration of multiple user profiles. A user with restore privileges could exploit this to obtain elevated privileges on the restored system.
Recommendations For IBM i version 7.4, ensure that user profiles are properly validated after a restore operation to prevent elevated privileges, and consider restricting access to the restore function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2019-4536

Affected Products

Db2 Mirror For I
Ibm I