CVE-2019-4652: IBM Spectrum Protect Plus

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.

Affected products

  • IBM Spectrum Protect Plus: from 10.1.0, up to and including 10.1.4

Published 2019-11-12. Last modified 2026-06-17.