CVE-2019-4381
Last modified
CVE-2019-4381 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC credentials. IBM X-Force ID: 162159.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | I | 7.2 |
| Ibm | I | 7.3 |
References
- http://www.securityfocus.com/bid/108808Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162159VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10887369Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108808Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162159VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10887369Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-4381?
How severe is CVE-2019-4381?
How do I fix CVE-2019-4381?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-4357When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.…6.7
- CVE-2019-4364IBM Maximo Asset Management 7.6 is vulnerable to CSV injecti…8
- CVE-2019-4366IBM Cognos Analytics 11.0 and 11.1 is susceptible to an info…5.3
- CVE-2019-4369Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-4377IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sens…4.3
- CVE-2019-4378IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0…6.5
- CVE-2019-4382IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unaut…5.3
- CVE-2019-4383When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.…6.7
- CVE-2019-4384IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to…4.3
- CVE-2019-4385IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS …6.5
- CVE-2019-4386IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Se…6.5
- CVE-2019-4387IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through…8.8
Are you affected by CVE-2019-4381?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
