cbcvebase.
CVE-2019-4294
published 2019-08-20

CVE-2019-4294: IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
ibmdatapower_gateway< 2018.4.1.72018.4.1.7
ibmdatapower_gateway
ibmdatapower_gateway
ibmdatapower_gateway
ibmdatapower_gateway
ibmdatapower_gateway
ibmdatapower_gateway2018.4.1.0 – 2018.4.1.6
ibmdatapower_gateway7.6.0.0 – 7.6.0.15
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance
ibmmq_appliance