CVE-2019-4038
MEDIUMIBM Security Identity Manager 6.0.0.0-6.0.0.19 - Code Injection
Title source: llmDescription
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
References (2)
Core 2
Core References
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/156162
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10869604
Scores
CVSS v3
6.2
EPSS
0.0044
EPSS Percentile
35.1%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
ibm/security_identity_manager
6.0.0.0 - 6.0.0.20
Published
Feb 04, 2019
Tracked Since
Feb 18, 2026