CVE-2019-4637: Input Validation
IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043.
Other sources
IBM Security Secret Server uses incomplete blocklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-4637.
What is the severity of CVE-2019-4637?
The severity of CVE-2019-4637 is medium with a severity score of 4.3.
What is the impact of CVE-2019-4637?
CVE-2019-4637 allows attackers to bypass application controls, which can result in a direct impact to the system and data integrity.
What software is affected by CVE-2019-4637?
IBM Security Secret Server versions up to and including 10.7.000059 are affected by CVE-2019-4637.
How can I fix CVE-2019-4637?
To fix CVE-2019-4637, it is recommended to update to a version of IBM Security Secret Server that is not affected by the vulnerability.