CVE-2019-4070
published 2019-06-07CVE-2019-4070: IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.67%
47.8th percentile
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | — | — |
| ibm | intelligent_operations_center | 5.1.0 – 5.2.0 | — |
| ibm | intelligent_operations_center_for_emergency_management | 5.1.0 – 5.1.0.6 | — |
| ibm | water_operations_for_waternamics | 5.1.0 – 5.2.1.1 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-86p3-5wp9-j3q8: IBM Intelligent Operations Center (IOC) 5
ghsa_unreviewed·2022-05-24
CVE-2019-4070 [MEDIUM] CWE-79 GHSA-86p3-5wp9-j3q8: IBM Intelligent Operations Center (IOC) 5
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 157015.
OSV
MariaDB vulnerabilities
osv·2019-08-12·CVSS 4.9
CVE-2019-2737 MariaDB vulnerabilities
MariaDB vulnerabilities
USN-4070-1 fixed multiple vulnerabilities in MySQL. This update provides the
corresponding fixes for CVE-2019-2737, CVE-2019-2739, CVE-2019-2740,
CVE-2019-2805 in MariaDB 10.1.
Ubuntu 18.04 LTS has been updated to MariaDB 10.1.41.
In addition to security fixes, the updated package contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://mariadb.com/kb/en/library/mariadb-10141-changelog/
https://mariadb.com/kb/en/library/mariadb-10141-release-notes/
Original advisory details:
Multiple security issues were discovered in MySQL and this update includes
a new upstream MySQL version to fix these issues.
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.04 have been updated to
MySQL 5.7.27.
In additi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-07
Published