First published: Mon Feb 04 2019(Updated: )
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Identity Manager | >=6.0.0.0<=6.0.0.20 | |
IBM Security Identity Manager | >=7.0.0.0<=7.0.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4038 is high with a CVSS score of 6.2.
Exploitation of CVE-2019-4038 can result in a limited form of code injection.
IBM Security Identity Manager versions 6.0.0.0 to 6.0.0.20 and versions 7.0.0.0 to 7.0.1.10 are affected by CVE-2019-4038.
An attacker can create unexpected control flow paths through the application, potentially bypassing security checks.
For more information about CVE-2019-4038, you can refer to the IBM X-Force ID: 156162 and the IBM support document.