CVE-2019-4570Information Exposure via Error Message in IBM Tivoli Netcool Impact

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 48.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22
Latest updateMay 24

Description

IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 166720.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDibm/tivoli_netcool_impact7.1.0.07.1.0.16
CVEListV5ibm/tivoli_netcool_impact7.1.0, 7.1.0.16+1

🔴Vulnerability Details

2
GHSA
GHSA-897x-rw4v-955q: IBM Tivoli Netcool Impact 72022-05-24
CVEList
CVE-2019-4570: IBM Tivoli Netcool Impact 72019-11-22
CVE-2019-4570 — Information Exposure via Error Message | cvebase