CVE-2019-9924: High severity IBM Data Risk Manager vulnerability
Bash could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by the failure to prevent the shell user from modifying BASHCMDS in the rbash. By modifying BASHCMDS, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the permissions of the shell.
Other sources
rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASHCMDS, thus allowing the user to execute any command with the permissions of the shell.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-9924.
What is the severity level of CVE-2019-9924?
The severity level of CVE-2019-9924 is high.
What is the affected software for CVE-2019-9924?
The affected software for CVE-2019-9924 includes Debian/bash, IBM Data Risk Manager, Ubuntu/bash, GNU Bash, openSUSE Leap, Netapp Hci Management Node, Netapp Solidfire, Canonical Ubuntu Linux.
How can I fix CVE-2019-9924 on Debian/bash?
To fix CVE-2019-9924 on Debian/bash, you can apply the recommended patches provided by the Debian security team.
Where can I find more information about CVE-2019-9924?
You can find more information about CVE-2019-9924 on the following references: [link1], [link2], [link3].