Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-4236

Опубликовано: 22 июл. 2019
Источник: nvd
CVSS3: 5.1
CVSS3: 4.4
CVSS2: 3.6
EPSS Низкий

Описание

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:ibm:spectrum_protect:*:*:*:*:*:*:*:*
Версия от 7.1.0.0 (включая) до 7.1.8.5 (включая)
cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00042
Низкий

5.1 Medium

CVSS3

4.4 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-19

Связанные уязвимости

CVSS3: 4.4
github
больше 3 лет назад

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.

EPSS

Процентиль: 13%
0.00042
Низкий

5.1 Medium

CVSS3

4.4 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-19