Untrusted search path in IBM Java SDK - CVE-2019-4732
Published: June 13, 2023
Vulnerability details
The vulnerability allows a local privileged user to execute arbitrary code on the target system.
The vulnerability exists due to DLL search order hijacking in Microsoft Windows client. A local privileged user can trick the victim into opening a specially-crafted file in a compromised folder and execute arbitrary code on the target system.
Affected software
IBM Cloud Transformation Advisor
IBM CICS TX on Cloud
How to mitigate CVE-2019-4732
IBM CICS TX on Cloud - update to 10.1.0.0 126165