PT-2020-5135 · Ibm+2 · Ibm Sdk+2

Honggang Ren

·

Published

2020-02-03

·

Updated

2020-03-18

·

CVE-2019-4732

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM SDK, Java Technology Edition versions 7.0.0.0 through 7.0.10.55 IBM SDK, Java Technology Edition versions 7.1.0.0 through 7.1.4.55 IBM SDK, Java Technology Edition versions 8.0.0.0 through 8.0.6.0
Description The issue is related to a DLL search order hijacking vulnerability in Microsoft Windows client. This could allow a local authenticated attacker to execute arbitrary code on the system by placing a specially-crafted file in a compromised folder.
Recommendations For versions 7.0.0.0 through 7.0.10.55, update to a version outside of this range to mitigate the risk. For versions 7.1.0.0 through 7.1.4.55, update to a version outside of this range to mitigate the risk. For versions 8.0.0.0 through 8.0.6.0, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to compromised folders to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05731
CVE-2019-4732
SUSE-SU-2020:0466-1
SUSE-SU-2020:0528-1
SUSE-SU-2020_0466-1
SUSE-SU-2020_0528-1

Affected Products

Ibm Sdk
Windows
Suse