CVE-2019-4539

CWE-913 documents3 sources
Severity
7.1HIGH
EPSS
0.3%
top 43.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 2
Latest updateMay 24

Description

IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. IBM X-Force ID: 165812.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:HExploitability: 2.8 | Impact: 4.2

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vpj2-4h83-h98j: IBM Security Directory Server 62022-05-24
CVEList
CVE-2019-4539: IBM Security Directory Server 62019-10-02