CVE-2019-4140Sensitive Information Exposure in IBM Spectrum Protect

Severity
7.1HIGHNVD
EPSS
0.0%
top 86.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 2
Latest updateMay 24

Description

IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databases by restoring old data. IBM X-Force ID: 158336.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

NVDibm/spectrum_protect7.1.0.07.1.9.300+1
CVEListV5ibm/spectrum_protect7.1, 8.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mf6v-qf3m-692g: IBM Tivoli Storage Manager Server (IBM Spectrum Protect 72022-05-24
CVEList
CVE-2019-4140: IBM Tivoli Storage Manager Server (IBM Spectrum Protect 72019-07-02
CVE-2019-4140 — Sensitive Information Exposure in IBM | cvebase