CVE-2019-4131: Medium severity ibm cloud application performance management vulnerability
IBM Application Performance Management (IBM Monitoring 8.1.4) could allow a remote attacker to induce the application to perform server-side DNS lookups of arbitrary domain names. IBM X-Force ID: 158270.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-4131?
CVE-2019-4131 has a high severity rating due to its potential to allow remote attackers to conduct unauthorized server-side DNS lookups.
How do I fix CVE-2019-4131?
To fix CVE-2019-4131, ensure that you update IBM Application Performance Management to a patched version provided by IBM.
What applications are affected by CVE-2019-4131?
CVE-2019-4131 affects IBM Application Performance Management version 8.1.4, both advanced and base private editions.
What type of attack is possible with CVE-2019-4131?
CVE-2019-4131 allows remote attackers to induce the application to perform DNS lookups of arbitrary domain names.
Is CVE-2019-4131 exploitable remotely?
Yes, CVE-2019-4131 is exploitable remotely, which increases the risk for organizations using the affected software.