Command Injection Vulnerability in IBM Security Secret Server
CVE-2019-4635
2.7LOW
Summary
IBM Security Secret Server version 10.7 is susceptible to a command injection vulnerability that enables a privileged user to execute unauthorized commands. This issue stems from improper input validation of special elements, allowing malicious actors to manipulate the application's behavior and potentially exploit the system. Users should apply relevant patches and follow best security practices to mitigate associated risks.
Affected Version(s)
Security Secret Server 10.7
References
CVSS V3.1
Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved