Insecure DLL loading in IBM Java SDK - CVE-2019-4473

 

Insecure DLL loading in IBM Java SDK - CVE-2019-4473

Published: June 15, 2023


Vulnerability identifier: #VU77343
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-4473
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise vulnerable system.

The vulnerability exists due to the usage of insecure absolute RPATHs. A local user can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into opening a file, associated with the vulnerable application, and execute arbitrary code on victim's system.


Affected software

IBM Java SDK
IBM Cloud Transformation Advisor
IBM Tivoli System Automation Application Manager
Tivoli System Automation for Multiplatforms

How to mitigate CVE-2019-4473

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 2.0.2
IBM Tivoli System Automation Application Manager - addressed in versions 4.1.0.1.0.13, 4.1.0.2.0.3
Tivoli System Automation for Multiplatforms - addressed in versions 4.1.0.3.0.10, 4.1.0.4.0.1, 4.1.0.4.0.7

External References

Related Security Bulletins