CVE-2019-4185
published 2019-06-06CVE-2019-4185: IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975.
PriorityP339high8.3CVSS 3.1
AVAACHPRNUINSCCHIHAH
EPSS
0.59%
44.3th percentile
IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server_on_cloud | — | — |
| linux | linux_kernel | >= 0 < 4.15.0-70.79 | 4.15.0-70.79 |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv3.08.3HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3g3-2r98-q7m9: IBM InfoSphere Information Server 11
ghsa_unreviewed·2022-05-24
CVE-2019-4185 [HIGH] GHSA-m3g3-2r98-q7m9: IBM InfoSphere Information Server 11
IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configured component. IBM X-Force ID: 158975.
OSV
linux, linux-hwe, linux-oem vulnerability and regression
osv·2019-11-13·CVSS 6.5
CVE-2019-0155 linux, linux-hwe, linux-oem vulnerability and regression
linux, linux-hwe, linux-oem vulnerability and regression
USN-4185-1 fixed vulnerabilities in the Linux kernel. It was discovered
that the kernel fix for CVE-2019-0155 (i915 missing Blitter Command
Streamer check) was incomplete on 64-bit Intel x86 systems. Also, the
update introduced a regression that broke KVM guests where extended
page tables (EPT) are disabled or not supported. This update addresses
both issues.
We apologize for the inconvenience.
Original advisory details:
Stephan van Schaik, Alyssa Milburn, Sebastian Österlund, Pietro Frigo,
Kaveh Razavi, Herbert Bos, Cristiano Giuffrida, Giorgi Maisuradze, Moritz
Lipp, Michael Schwarz, Daniel Gruss, and Jo Van Bulck discovered that Intel
processors using Transactional Synchronization Extensions (TSX) could
expose memory contents
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-06
Published