Code Injection and Privilege Elevation in IBM SDK on AIX Platform
CVE-2019-4473

8.4HIGH

Key Information:

Vendor
IBM
Status
Vendor
CVE Published:
5 August 2019

Summary

Multiple binaries within IBM SDK, Java Technology Edition versions 7 and 8 on the AIX platform have been found to utilize insecure absolute RPATHs. This security flaw may allow local users to exploit the system, potentially leading to unauthorized code execution and elevation of privileges. Users of affected versions should take immediate action to mitigate this vulnerability.

Affected Version(s)

Java 7

Java 7R1

Java 8

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.