CVE-2019-9203: Critical severity nagios incident manager vulnerability
Published Mar 28, 2019
·Updated
Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
Affected Software
1 affected component
Nagios Incident Manager<2.2.7
Event History
Mar 28, 2019
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9203?
CVE-2019-9203 is classified as a high severity vulnerability due to the potential for unauthorized incident closure via the API.
2
How do I fix CVE-2019-9203?
To fix CVE-2019-9203, update Nagios IM to version 2.2.7 or later.
3
What type of attack does CVE-2019-9203 enable?
CVE-2019-9203 enables an authorization bypass attack allowing users to close incidents they should not have permissions for.
4
Which versions of Nagios IM are affected by CVE-2019-9203?
CVE-2019-9203 affects all versions of Nagios IM prior to version 2.2.7.
5
Is CVE-2019-9203 related to any other vulnerabilities?
CVE-2019-9203 is specifically regarding an API authorization bypass in Nagios IM, and does not indicate direct relationships with other vulnerabilities.