CVE-2019-4679
MEDIUMCVSS 4.3/10EPSS 0.82%
Last modified
CVE-2019-4679 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force ID: 171515.. EPSS estimates a 0.82% chance of exploitation in the next 30 days.
Description
IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force ID: 171515.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Content Navigator | 3.0.0 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171515VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/1283458Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/171515VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/1283458Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-4679?
IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and version that could be used in further attacks against the system. IBM X-Force ID: 171515.
How severe is CVE-2019-4679?
CVE-2019-4679 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.82% probability of exploitation in the next 30 days.
How do I fix CVE-2019-4679?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-4670IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 coul…6.5
- CVE-2019-4671IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to…6.3
- CVE-2019-4672IBM QRadar Advisor 1.1 through 2.5 could allow an unauthoriz…5.3
- CVE-2019-4674IBM Security Identity Manager 7.0.1 could allow a remote att…4.9
- CVE-2019-4675IBM Security Identity Manager 7.0.1 contains hard-coded cred…9.8
- CVE-2019-4676IBM Security Identity Manager Virtual Appliance 7.0.2 stores…7.8
- CVE-2019-4680IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through…8.8
- CVE-2019-4681IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulner…6.1
- CVE-2019-4686IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not…5.3
- CVE-2019-4687IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores s…5.3
- CVE-2019-4688IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not…4.3
- CVE-2019-4689IBM Security Guardium Data Encryption (GDE) 3.0.0.2 could al…7.5
Are you affected by CVE-2019-4679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
