3.6
CVSSv2

CVE-2019-4236

Published: 22/07/2019 Updated: 02/12/2022
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 2.5 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local malicious user to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm spectrum_protect