Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-4536

Опубликовано: 29 авг. 2019
Источник: nvd
CVSS3: 6.7
CVSS3: 6.3
CVSS2: 3.3
EPSS Низкий

Описание

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

6.7 Medium

CVSS3

6.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 6.3
github
больше 3 лет назад

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles. A user with restore privileges could exploit this vulnerability to obtain elevated privileges on the restored system. IBM X-Force ID: 165592.

EPSS

Процентиль: 12%
0.0004
Низкий

6.7 Medium

CVSS3

6.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-269