CVE-2019-4013
critical · 9IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
9
CVSS
13.9%
EPSS (exploit prob.)
96th
EPSS percentile
2019-04-10
Published
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | bigfix_platform | >= 9.5.0, <= 9.5.11 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html
- http://www.ibm.com/support/docview.wss?uid=ibm10874666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155887
- http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html
- http://www.ibm.com/support/docview.wss?uid=ibm10874666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155887
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-4013