CVE-2019-4635

CWE-77Command Injection3 documents3 sources
Severity
2.7LOW
EPSS
1.0%
top 22.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 28
Latest updateMay 24

Description

IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages2 packages

NVDibm/security_secret_server< 10.7.000059

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3xgx-wrc3-hjjj: IBM Security Secret Server 102022-05-24
CVEList
CVE-2019-4635: IBM Security Secret Server 102020-01-28
CVE-2019-4635 (LOW CVSS 2.7) | IBM Security Secret Server 10.7 cou | cvebase.io