Vulnerability Details CVE-2019-4357
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.4%
CVSS Severity
CVSS v3 Score 8.2
CVSS v2 Score 7.2
Products affected by CVE-2019-4357
-
cpe:2.3:a:ibm:spectrum_protect_plus:10.1.1
-
cpe:2.3:a:ibm:spectrum_protect_plus:10.1.2
-
cpe:2.3:a:ibm:spectrum_protect_plus:10.1.3