CVE-2019-4093 describes a file permission vulnerability in IBM Spectrum Protect (formerly Tivoli Storage Manager) Client Web User Interface on Windows, affecting versions up to 8.1.7. An authenticated local attacker could exploit this to restore files and directories they should not have access to, leading to unauthorized information disclosure and modification. With a CVSS score of 4.4 (Medium), this vulnerability has a low attack complexity and requires local user privileges, but does not appear to be actively exploited, nor is public exploit code or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1.7CPE matchmatch criteria | cpe:2.3:a:ibm:spectrum_protect:8.1.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.