Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-14271 |
CWE-ID | CWE-427 |
Exploitation vector | Local |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software Subscribe |
IBM Cloud Automation Manager Server applications / Other server solutions |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU20969
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2019-14271
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to the application loads NSS libraries in docker cp
in an insecure manner. A local attacker can pass a specially crafted library file to the application and execute arbitrary code on the system with elevated privileges.
Install update from vendor's website.
Vulnerable software versionsIBM Cloud Automation Manager: All versions
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/1072204
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?