PT-2019-17146 · Ibm · Ibm Spectrum Protect Plus

Published

2019-11-12

·

Updated

2019-11-14

·

CVE-2019-4652

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions IBM Spectrum Protect Plus versions 10.1.0 through 10.1.4
Description The issue allows a local user to obtain sensitive information or perform unauthorized actions due to insecure file permissions on restored files and directories in Windows.
Recommendations For IBM Spectrum Protect Plus versions 10.1.0 through 10.1.4, update to a version that addresses the insecure file permissions issue to prevent unauthorized access and actions.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4652

Affected Products

Ibm Spectrum Protect Plus