Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-4294


IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.


Published

2019-08-20T19:15:11.730

Last Modified

2024-11-21T04:43:26.147

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm datapower_gateway < 2018.4.1.7 Yes
Application ibm datapower_gateway ≤ 7.6.0.15 Yes
Application ibm datapower_gateway ≤ 2018.4.1.6 Yes
Application ibm mq_appliance ≤ 8.0.0.12 Yes
Application ibm mq_appliance ≤ 9.1.0.2 Yes
Application ibm mq_appliance ≤ 9.1.2 Yes

References