VulnerabilityModified
CVE-2019-4038
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks.
MEDIUM 6.2EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
- CVSS 3.1
- 6.2 MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ibm/security identity manager
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/156162VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10869604Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/156162VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10869604Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.