First published: Tue Aug 13 2019(Updated: )
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataPower Gateway | <2018.4.1.7 | |
IBM DataPower Gateway | >=7.6.0.0<=7.6.0.15 | |
IBM DataPower Gateway | >=2018.4.1.0<=2018.4.1.6 | |
IBM MQ Appliance | >=8.0.0.0<=8.0.0.12 | |
IBM MQ Appliance | >=9.1.0.0<=9.1.0.2 | |
IBM MQ Appliance | >=9.1.1<=9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4294 is a command injection vulnerability in IBM DataPower Gateway and IBM MQ Appliance that allows a local attacker to execute arbitrary commands on the system.
The severity of CVE-2019-4294 is high, with a CVSS score of 7.8.
IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15, and IBM MQ Appliance versions 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 are affected.
A local attacker can exploit CVE-2019-4294 by injecting arbitrary commands into the affected system.
Yes, you can find more information about CVE-2019-4294 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/160701), [Reference 2](https://www.ibm.com/support/docview.wss?uid=ibm10887005), [Reference 3](https://www.ibm.com/support/docview.wss?uid=ibm10958933).