CVE-2019-4068
published 2019-06-07CVE-2019-4068: IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.48%
71.1th percentile
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | 5.1.0 – 5.2.0 | — |
| ibm | intelligent_operations_center_for_emergency_management | 5.1.0 – 5.1.0.6 | — |
| ibm | water_operations_for_waternamics | 5.1.0 – 5.2.1.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7c29-cxg2-pvwr: IBM Intelligent Operations Center (IOC) 5
ghsa_unreviewed·2022-05-24
CVE-2019-4068 [HIGH] CWE-307 GHSA-7c29-cxg2-pvwr: IBM Intelligent Operations Center (IOC) 5
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.
OSV
linux-hwe, linux-gcp vulnerabilities
osv·2019-07-23·CVSS 7.8
linux-hwe, linux-gcp vulnerabilities
linux-hwe, linux-gcp vulnerabilities
USN-4068-1 fixed vulnerabilities in the Linux kernel for Ubuntu
18.04 LTS. This update provides the corresponding updates for the
Linux Hardware Enablement (HWE) kernel from Ubuntu 18.04 for Ubuntu
16.04 LTS.
Adam Zabrocki discovered that the Intel i915 kernel mode graphics driver in
the Linux kernel did not properly restrict mmap() ranges in some
situations. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-11085)
It was discovered that a race condition leading to a use-after-free existed
in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux
kernel. The RDS protocol is disabled via blocklist by default in Ubuntu.
If enabled, a local attacker could use this
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-07
Published