CVE-2019-4069

Severity
8.8HIGH
EPSS
0.4%
top 36.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 24

Description

IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5ibm/intelligent_operations_center16 versions+15
NVDibm/water_operations5.1.05.2.1.1

🔴Vulnerability Details

3
GHSA
GHSA-4v99-jhjf-8p4p: IBM Intelligent Operations Center (IOC) 52022-05-24
OSV
linux-hwe vulnerabilities2019-08-01
CVEList
CVE-2019-4069: IBM Intelligent Operations Center (IOC) 52019-06-07

💬Community

2
Bugzilla
CVE-2019-14863 angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes2019-10-21
Bugzilla
CVE-2019-14862 knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.2019-10-21
CVE-2019-4069 (HIGH CVSS 8.8) | IBM Intelligent Operations Center ( | cvebase.io