CVE-2019-4069
published 2019-06-07CVE-2019-4069: IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM…
PriorityP344high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.43%
69.9th percentile
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | 5.1.0 – 5.2.0 | — |
| ibm | intelligent_operations_center_for_emergency_management | 5.1.0 – 5.1.0.6 | — |
| ibm | water_operations_for_waternamics | 5.1.0 – 5.2.1.1 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4v99-jhjf-8p4p: IBM Intelligent Operations Center (IOC) 5
ghsa_unreviewed·2022-05-24
CVE-2019-4069 [HIGH] CWE-434 GHSA-4v99-jhjf-8p4p: IBM Intelligent Operations Center (IOC) 5
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.
OSV
linux-hwe vulnerabilities
osv·2019-08-01·CVSS 7.8
linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-4069-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu 18.04 LTS.
It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)
Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)
It was discovered that the ext4 file system implementation in the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14863 angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
bugzilla·2019-10-21·CVSS 6.1
CVE-2019-14863 [MEDIUM] CVE-2019-14863 angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
CVE-2019-14863 angular: Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes
This is done by escaping the context of the web application; the web application then delivers that data to its users along with other trusted dynamic content, without validating it.
Discussion:
External References:
https://snyk.io/vuln/npm:angular:20150807
---
This issue has been addressed in the following products:
Red Hat Decision Manager
Via RHSA-2019:4069 https://access.redhat.com/errata/RHSA-2019:4069
---
This issue has been addressed in the following products:
Red Hat Process Automation
Via RHSA-2019:4071 https://access.redhat.com/errata/RHSA-2019:4071
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https:/
Bugzilla
CVE-2019-14862 knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
bugzilla·2019-10-21·CVSS 6.1
CVE-2019-14862 [MEDIUM] CVE-2019-14862 knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
CVE-2019-14862 knockout: Cross-site Scripting (XSS) attacks due to not escaping the name attribute.
This is done by escaping the context of the web application; the web application then delivers that data to its users along with other trusted dynamic content, without validating it.
Upstream issue:
https://github.com/knockout/knockout/issues/1244
Upstream patch:
https://github.com/knockout/knockout/pull/2345
https://github.com/knockout/knockout/commit/7e280b2b8a04cc19176b5171263a5c68bda98efb
Discussion:
External References:
https://snyk.io/vuln/npm:knockout:20180213
---
This issue has been addressed in the following products:
Red Hat Decision Manager
Via RHSA-2019:4069 https://access.redhat.com/errata/RHSA-2019:4069
---
This issue has been addressed in the following products:
2019-06-07
Published