CVE-2019-4298
published 2019-07-01CVE-2019-4298: IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to…
PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.32%
24.2th percentile
IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | sqlite3 | >= 0 < 3.8.2-1ubuntu2.2+esm2 | 3.8.2-1ubuntu2.2+esm2 |
| ibm | robotic_process_automation_with_automation_anywhere | — | — |
| ibm | robotic_process_automation_with_automation_anywhere | >= 11.0.0.0 < 11.0.0.5 | 11.0.0.5 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv3.07.7HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-455c-2fpr-g47j: IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local use
ghsa_unreviewed·2022-05-24
CVE-2019-4298 [HIGH] GHSA-455c-2fpr-g47j: IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local use
IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764.
OSV
sqlite3 vulnerabilities
osv·2020-08-03·CVSS 8.8
CVE-2019-13734 sqlite3 vulnerabilities
sqlite3 vulnerabilities
USN-4298-1 fixed several vulnerabilities in SQLite. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that SQLite incorrectly handled certain shadow tables. An
attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13734,
CVE-2019-13750, CVE-2019-13752, CVE-2019-13753)
It was discovered that SQLite incorrectly handled certain corrupt records.
An attacker could use this issue to cause SQLite to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-13751)
It was discovered that SQLite incorrectly handled errors during parsing. An
attacker could use this issue to cause SQLite to crash, resu
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-07-01
Published