First published: Wed Jan 08 2020(Updated: )
IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass application controls resulting in direct impact to the system and data integrity. IBM X-Force ID: 170043.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Secret Server | <10.7.000059 | |
<=All |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-4637.
The severity of CVE-2019-4637 is medium with a severity score of 4.3.
CVE-2019-4637 allows attackers to bypass application controls, which can result in a direct impact to the system and data integrity.
IBM Security Secret Server versions up to and including 10.7.000059 are affected by CVE-2019-4637.
To fix CVE-2019-4637, it is recommended to update to a version of IBM Security Secret Server that is not affected by the vulnerability.