CVE-2019-4054
published 2019-07-17CVE-2019-4054: IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks…
PriorityP49low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.33%
25.7th percentile
IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | qradar_security_information_and_event_manager | 7.2.0 – 7.2.8.15 | — |
| ibm | qradar_security_information_and_event_manager | 7.3.0 – 7.3.2 | — |
| ibm | qradar_siem | — | — |
| ibm | qradar_siem | — | — |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.16.04.1 | 68.0.1+build1-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 68.0.1+build1-0ubuntu0.18.04.1 | 68.0.1+build1-0ubuntu0.18.04.1 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-crp2-c5rh-r33x: IBM QRadar SIEM 7
ghsa_unreviewed·2022-05-24
CVE-2019-4054 [LOW] GHSA-crp2-c5rh-r33x: IBM QRadar SIEM 7
IBM QRadar SIEM 7.2 and 7.3 could allow a local user to obtain sensitive information when exporting content that could aid an attacker in further attacks against the system. IBM X-Force ID: 156563.
OSV
firefox regressions
osv·2019-07-25·CVSS 9.8
CVE-2019-9811 firefox regressions
firefox regressions
USN-4054-1 fixed vulnerabilities in Firefox. The update introduced
various minor regressions. This update fixes the problems.
We apologize for the inconvenience.
Original advisory details:
A sandbox escape was discovered in Firefox. If a user were tricked in to
installing a malicious language pack, an attacker could exploit this to
gain additional privileges. (CVE-2019-9811)
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information, bypass same origin restrictions, conduct cross-site scripting
(XSS) attacks, conduct cross-site request forgery (CSRF) attacks, spoof
origin attributes, spoof the addressbar
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-17
Published