VulnerabilityModified
CVE-2019-4234
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor.
MEDIUM 4.3EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: 159416.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Affected
- ibm/pureapplication system
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/159416VDB Entry, Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10885602Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/159416VDB Entry, Vendor Advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10885602Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.