CVE-2019-4088

3 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 75.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 2
Latest updateMay 24

Description

IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on the system, caused by loading a specially crafted library loaded by the dsmqsan module. By setting up such a library, a local attacker could exploit this vulnerability to gain root privileges on the vulnerable system. IBM X-Force ID: 157511.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/spectrum_protect_operations_center7.1.0.0007.1.9.200+1
CVEListV5ibm/spectrum_protect7.1, 8.1+1

🔴Vulnerability Details

2
GHSA
GHSA-x859-ppjw-c734: IBM Spectrum Protect Servers 72022-05-24
CVEList
CVE-2019-4088: IBM Spectrum Protect Servers 72019-07-02
CVE-2019-4088 (HIGH CVSS 7.8) | IBM Spectrum Protect Servers 7.1 an | cvebase.io