When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirected restore operation specifying a target path may allow execution of arbitrary code on the system. IBM X-Force ID: 161667,
2019-07-01T15:15:13.053
2024-11-21T04:43:30.500
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | spectrum_protect_plus | 10.1.1 | Yes |
Application | ibm | spectrum_protect_plus | 10.1.2 | Yes |
Application | ibm | spectrum_protect_plus | 10.1.3 | Yes |