IBM Spectrum Protect Plus agent files on Windows have incorrect access permissions.
CVEID:CVE-2020-4631
**DESCRIPTION:**IBM Spectrum Protect Plus agent files, in non-default configurations, on Windows are assigned access to everyone with full control permissions, which could allow a local user to cause interruption of the service operations.
CVSS Base score: 5.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/185372 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM Spectrum Protect Plus | 10.1.0-10.1.6 |
Spectrum Protect Plus Release|First Fixing VRM Level|Platform|**APAR
**|Link to Fix
—|—|—|—|—
10.1| 10.1.6 ifix2| Linux| IT33149 | <https://www.ibm.com/support/pages/node/6254732>
None