DNA View

CVE-2019-4732

Medium
Low Medium High Critical
6.5
CVSS Score
Published: Feb 03, 2020
Last Modified: Nov 21, 2024

Vulnerability Description

IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
H
User Interaction
R
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

4 configuration(s) from 1 vendor(s)

websphere_application_server
Version:
8.5
CPE:
cpe:2.3:a:ibm:websphere_application_server:8.5:*:*:*:traditional:*:*:*
websphere_application_server
Version:
8.0
CPE:
cpe:2.3:a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:*
websphere_application_server
Version:
9.0
CPE:
cpe:2.3:a:ibm:websphere_application_server:9.0:*:*:*:*:*:*:*
websphere_application_server
Version:
7.0
CPE:
cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:*
This vulnerability affects 4 software configuration(s). Ensure you patch all affected systems.

Severity Details

6.5
out of 10.0
Medium

Weakness Type (CWE)

CWE-426

Untrusted Search Path

Description
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Exploit Likelihood
High
Typical Severity
High
Abstraction Level
Base

Key Information

Published Date
February 03, 2020