XML Injection Vulnerability in IBM Security Directory Server
CVE-2019-4539

7.1HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 October 2019

Summary

IBM Security Directory Server 6.4.0 has a vulnerability where it fails to adequately sanitize special elements in XML inputs. This flaw allows attackers to modify the syntax or commands within the XML before it is processed by the target system, potentially leading to unauthorized actions and data exposure. It is crucial for users of this version to apply the recommended patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Security Directory Server 6.4.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.