CVE-2019-4157
published 2019-06-25CVE-2019-4157: IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in…
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.89%
55.3th percentile
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | — | — |
| ibm | security_access_manager | 9.0.1 – 9.0.6 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pj2f-836m-422x: IBM Security Access Manager 9
ghsa_unreviewed·2022-05-24
CVE-2019-4157 [MEDIUM] CWE-79 GHSA-pj2f-836m-422x: IBM Security Access Manager 9
IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 158573.
OSV
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
osv·2019-10-22·CVSS 7.8
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
linux-hwe, linux-azure, linux-gcp, linux-gke-5.0 vulnerabilities
USN-4157-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04.
This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu
18.04 LTS.
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-14814,
CVE-2019-14815, CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-25
Published