First published: Fri Jun 14 2019(Updated: )
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | =7.2 | |
IBM OS/400 | =7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4381 is classified as high due to the potential for sensitive information exposure.
To fix CVE-2019-4381, update your IBM i operating system to the latest version that addresses this vulnerability.
CVE-2019-4381 affects IBM i versions 7.2 and 7.3.
CVE-2019-4381 allows local attackers to obtain sensitive HMC credentials.
CVE-2019-4381 is exploited using the REST API for advanced node failure detection in IBM i clustering.