Security Advisory

CVE-2019-4236

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-07-22 13:35:13
Last updated 2024-09-16 23:06:20
Assigner ibm
State PUBLISHED

Description

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.