IBM Spectrum Protect Plus is prone to insecure file-permission vulnerability. An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks. IBM Spectrum Protect Plus versions 10.1.0 through 10.1.4 are vulnerable.
Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells.
Grant local interactive access to affected computers for trusted and accountable users only.
Run all software as a nonprivileged user with minimal access rights.
Run all non-administrative software as a non-administrative user with the least amount of privileges required to successfully operate. This will greatly reduce the potential damage that successful exploitation may achieve.
Do not follow links provided by unknown or untrusted sources.
Never follow links provided by unknown or untrusted sources.
Updates are available. Please see the references or vendor advisory for more information.