CVE-2019-4237
published 2019-07-01CVE-2019-4237: A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside…
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.67%
47.8th percentile
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | spamassassin | >= 0 < 3.4.2-0ubuntu0.14.04.1+esm1 | 3.4.2-0ubuntu0.14.04.1+esm1 |
| ibm | infosphere_information_governance_catalog | — | — |
| ibm | infosphere_information_governance_catalog | — | — |
| ibm | infosphere_information_governance_catalog | — | — |
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server | — | — |
| ibm | infosphere_information_server_on_cloud | — | — |
| ibm | infosphere_information_server_on_cloud | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gvqm-hqhp-9mhq: A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11
ghsa_unreviewed·2022-05-24
CVE-2019-4237 [MEDIUM] CWE-79 GHSA-gvqm-hqhp-9mhq: A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11
A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. IBM X-Force ID: 159419.
OSV
spamassassin vulnerabilities
osv·2020-01-15·CVSS 6.7
CVE-2018-11805 spamassassin vulnerabilities
spamassassin vulnerabilities
USN-4237-1 fixed several vulnerabilities in SpamAssassin. This update provides
the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM.
Original advisory details:
It was discovered that SpamAssassin incorrectly handled certain CF files.
If a user or automated system were tricked into using a specially-crafted
CF file, a remote attacker could possibly run arbitrary code.
(CVE-2018-11805)
It was discovered that SpamAssassin incorrectly handled certain messages.
A remote attacker could possibly use this issue to cause SpamAssassin to
consume resources, resulting in a denial of service. (CVE-2019-12420)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-01
Published