CVE-2019-4562

Severity
5.3MEDIUM
EPSS
0.3%
top 48.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateMay 24

Description

IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/security_directory_server6.4.0.06.4.0.20

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3g8x-qh85-fr9c: IBM Security Directory Server 62022-05-24
CVEList
CVE-2019-4562: IBM Security Directory Server 62020-02-04