CVE detail
CVE-2019-4236 — CVE-2019-4236
Published 2019-07-22 · Modified 2026-06-17 · Vendor ibm · Product spectrum_protect · Source nvd
MEDIUM
severity
CVSS-derived band
0.0032
EPSS probability
exploitation probability, 30d
25.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References