CVE-2019-4672
Last modified
CVE-2019-4672 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially crafted HTTP requests that could aid in further attacks against the system. IBM X-Force ID: 171438.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qradar Advisor | >= 1.1, < 2.5.1 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171438VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/3379965Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171438VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/3379965Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-4672?
How severe is CVE-2019-4672?
How do I fix CVE-2019-4672?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-4666IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1…2.3
- CVE-2019-4667IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote atta…5.9
- CVE-2019-4668IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials i…5.5
- CVE-2019-4669IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06…6.3
- CVE-2019-4670IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 coul…6.5
- CVE-2019-4671IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to…6.3
- CVE-2019-4674IBM Security Identity Manager 7.0.1 could allow a remote att…4.9
- CVE-2019-4675IBM Security Identity Manager 7.0.1 contains hard-coded cred…9.8
- CVE-2019-4676IBM Security Identity Manager Virtual Appliance 7.0.2 stores…7.8
- CVE-2019-4679IBM Content Navigator 3.0CD could allow an authenticated use…4.3
- CVE-2019-4680IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through…8.8
- CVE-2019-4681IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulner…6.1
Are you affected by CVE-2019-4672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
