| Vulnerability Name: | CVE-2019-4558 (CCN-166282) | ||||||||||||
| Assigned: | 2019-10-07 | ||||||||||||
| Published: | 2019-10-07 | ||||||||||||
| Updated: | 2019-10-11 | ||||||||||||
| Summary: | A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spectrum Scale V4.2.0.0 through V4.2.3.17 that could allow a local attacker to obtain root privilege by injecting parameters into setuid files. | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-74 | ||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-4558 Source: XF Type: UNKNOWN ibm-spectrum-cve20194558-priv-escalation(166282) Source: XF Type: VDB Entry, Vendor Advisory ibm-spectrum-cve20194558-priv-escalation (166282) Source: CCN Type: IBM Security Bulletin 1073732 (Spectrum Scale) A vulnerability has been identified in IBM Spectrum Scale where the local attacker can obtain root privilege by injecting parameters into setuid files (CVE-2019-4558) Source: CONFIRM Type: Mitigation, Patch, Vendor Advisory https://www.ibm.com/support/pages/node/1073732 Source: CCN Type: IBM Security Bulletin 1118991 (Elastic Storage Server) IBM Spectrum Scale for IBM Elastic Storage Server is affected where the local attacker can obtain root privilege by injecting parameters into setuid files (CVE-2019-4558) Source: CCN Type: IBM Security Bulletin 1170418 (DB2 for Linux- UNIX and Windows) IBM Db2 LUW on AIX and Linux Affected by a Vulnerability in IBM Spectrum Scale (CVE-2019-4558) Source: CCN Type: IBM Security Bulletin 6212133 (Storwize V7000 Unified (2073)) IBM Storwize V7000 Unified is affected by vulnerability in GPFS (CVE-2019-4558) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||