CVE-2019-4637
CVE-2019-4637
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
28 Jan 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043.
CVSS:3.0/A:N/S:U/PR:L/UI:N/AV:N/C:N/I:L/AC:L/RC:C/RL:O/E:U
Affected products
IBM · Security Secret Server