CVE-2019-4225
published 2019-06-26CVE-2019-4225: IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID…
PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.35%
27.2th percentile
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | — | — |
| ibm | pureapplication_system | 2.2.3.0 – 2.2.5.3 | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j46j-hr86-qf36: IBM PureApplication System 2
ghsa_unreviewed·2022-05-24
CVE-2019-4225 [MEDIUM] CWE-532 GHSA-j46j-hr86-qf36: IBM PureApplication System 2
IBM PureApplication System 2.2.3.0 through 2.2.5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 159242.
OSV
linux-hwe vulnerabilities
osv·2020-01-18·CVSS 9.8
CVE-2019-14895 linux-hwe vulnerabilities
linux-hwe vulnerabilities
USN-4225-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 19.10 for Ubuntu 18.04 LTS.
It was discovered that a heap-based buffer overflow existed in the Marvell
WiFi-Ex Driver for the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2019-14895, CVE-2019-14901)
It was discovered that a heap-based buffer overflow existed in the Marvell
Libertas WLAN Driver for the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2019-14896, CVE-2019-14897)
It was discover
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-26
Published