cbcvebase.
CVE-2019-4038
published 2019-02-04

CVE-2019-4038: IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing…

PriorityP422medium6.2CVSS 3.1
AVPACLPRHUINSUCHIHAH
EPSS
0.44%
35.4th percentile
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

Affected

5 ranges
VendorProductVersion rangeFixed in
bzipbzip2>= 0 < 1.0.6-5ubuntu0.1~esm11.0.6-5ubuntu0.1~esm1
ibmsecurity_identity_manager
ibmsecurity_identity_manager
ibmsecurity_identity_manager6.0.0.0 – 6.0.0.20
ibmsecurity_identity_manager7.0.0.0 – 7.0.1.10

CVSS provenance

nvdv3.16.2MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.