CVE-2019-4038
published 2019-02-04CVE-2019-4038: IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing…
PriorityP422medium6.2CVSS 3.1
AVPACLPRHUINSUCHIHAH
EPSS
0.44%
35.4th percentile
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bzip | bzip2 | >= 0 < 1.0.6-5ubuntu0.1~esm1 | 1.0.6-5ubuntu0.1~esm1 |
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | — | — |
| ibm | security_identity_manager | 6.0.0.0 – 6.0.0.20 | — |
| ibm | security_identity_manager | 7.0.0.0 – 7.0.1.10 | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.2HIGHCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wxw-jxm6-5ch2: IBM Security Identity Manager 6
ghsa_unreviewed·2022-05-13
CVE-2019-4038 [MEDIUM] CWE-94 GHSA-4wxw-jxm6-5ch2: IBM Security Identity Manager 6
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
OSV
bzip2 vulnerabilities
osv·2019-06-26·CVSS 6.5
CVE-2016-3189 bzip2 vulnerabilities
bzip2 vulnerabilities
USN-4038-1 fixed several vulnerabilities in bzip2. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Aladdin Mubaied discovered that bzip2 incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-3189)
It was discovered that bzip2 incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-12900)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-04
Published