CVE-2019-4473: Code Injection
Published Aug 5, 2019
·Updated
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
Affected Software
3 affected components
IBM JDK=7.0.0.0
IBM JDK=7.1.4.50
IBM JDK=8.0
Event History
Aug 5, 2019
CVE Published
via MITRE·01:40 PM
Data Sourced
via MITRE·01:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-4473.
2
What is the severity of CVE-2019-4473?
The severity of CVE-2019-4473 is high (7.8).
3
What is the affected software of CVE-2019-4473?
The affected software of CVE-2019-4473 is IBM SDK Java Technology Edition 7, 7R, and 8 on the AIX platform.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by local users to facilitate code injection and privilege elevation.
5
How can I fix CVE-2019-4473?
To fix CVE-2019-4473, update to the latest version of IBM SDK Java Technology Edition 7, 7R, or 8 on the AIX platform.