CVE-2019-4465

Severity
3.3LOW
EPSS
0.1%
top 76.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3
Latest updateMay 24

Description

IBM Cloud Pak System 2.3 and 2.3.0.1 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 163774.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/cloud_pak_system2.2, 2.3+1
NVDibm/cloud_pak_system2.3, 2.3.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-54x3-6856-52f3: IBM Cloud Pak System 22022-05-24
CVEList
CVE-2019-4465: IBM Cloud Pak System 22019-12-03

📋Vendor Advisories

1
Red Hat
struts: Possible DoS attack when using URLValidator2016-06-17

💬Community

1
Bugzilla
CVE-2016-4465 struts: Possible DoS attack when using URLValidator2016-06-20
CVE-2019-4465 (LOW CVSS 3.3) | IBM Cloud Pak System 2.3 and 2.3.0. | cvebase.io