CVE ID: CVE-2019-4031 Description: IBM Tivoli Workload Scheduler contains a vulnerability allowing a local user to launch taskLauncher program and escalate privileges by writing files as root. CVSS Scores: - Base Score: 8.4 - Temporal Score: [Varying, check the provided link for current score] Affected Products and Versions: - Tivoli Workload Scheduler Distributed 9.2.0 FP03 and earlier - IBM Workload Scheduler Distributed 9.3.0 FP03 and earlier - IBM Workload Scheduler Distributed 9.4.0 FP05 and earlier - IBM Workload Scheduler Distributed 9.5.0 GA Remediation/Fixes: APAR IJ15085 addresses the vulnerability. Fixes are available for download on FixCentral for specific versions. Operating Systems: AIX, HP-UX, Linux, Solaris Reported By: Davide Ciocia - Senior Security Engineer at ING