CVE-2019-4541: Input Validation
IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 165814.
Other sources
IBM Security Directory Server uses incomplete blocklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-4541.
What is the severity level of CVE-2019-4541?
The severity level of CVE-2019-4541 is high with a CVSS score of 7.2.
What is the affected software?
The affected software is IBM Security Directory Server version 6.4.0.
How does this vulnerability impact the system and data integrity?
This vulnerability allows attackers to bypass application controls, resulting in direct impact to the system and data integrity.
Is there any additional information available?
Yes, you can find additional information at the following links: [https://exchange.xforce.ibmcloud.com/vulnerabilities/165814](https://exchange.xforce.ibmcloud.com/vulnerabilities/165814) and [https://www.ibm.com/support/pages/node/1288660](https://www.ibm.com/support/pages/node/1288660).