CVE-2019-4286
published 2020-04-29CVE-2019-4286: IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to…
PriorityP416medium4.3CVSS 3.1
AVPACLPRLUINSUCHINAN
EPSS
0.34%
26.0th percentile
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | maximo_anywhere | — | — |
| ibm | maximo_anywhere | — | — |
| ibm | maximo_anywhere | — | — |
| ibm | maximo_anywhere | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.04.3MEDIUMCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67ph-m43p-rm6c: IBM Maximo Anywhere 7
ghsa_unreviewed·2022-05-24
CVE-2019-4286 [LOW] CWE-200 GHSA-67ph-m43p-rm6c: IBM Maximo Anywhere 7
IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Force ID: 160514.
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2020-02-18·CVSS 5.5
CVE-2019-14615 linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-4286-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM.
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition existed in the Softmac USB Prism54
device driver in the Linux kernel. A physically proximate attacker could
use this to cause a denial of service (system crash). (CVE-2019-15220)
Julien Grall discovered that the Xen balloon memory driver in the Linux
kernel did not properly rest
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-29
Published