CVE-2019-4058

CWE-1021Clickjacking3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.1%
top 73.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Latest updateMay 24

Description

IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements and information normally restricted to administrators. IBM X-Force ID: 156570.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/bigfix_platform9.29.2.17+1
CVEListV5ibm/bigfix_platform9.2, 9.5+1

🔴Vulnerability Details

2
GHSA
GHSA-9j2c-29hq-3vcm: IBM BigFix Platform 92022-05-24
CVEList
CVE-2019-4058: IBM BigFix Platform 92019-05-20
CVE-2019-4058 (MEDIUM CVSS 6.5) | IBM BigFix Platform 9.2 and 9.5 cou | cvebase.io