Lucene search

K
cve[email protected]CVE-2019-4741
HistoryFeb 12, 2020 - 4:15 p.m.

CVE-2019-4741

2020-02-1216:15:11
CWE-918
web.nvd.nist.gov
26
ibm
content navigator
3.0cd
vulnerability
ssrf
server side request forgery
ibm x-force
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.

Affected configurations

Vulners
NVD
Node
ibmcontent_navigatorMatch3.0continuous_delivery
VendorProductVersionCPE
ibmcontent_navigator3.0cpe:2.3:a:ibm:content_navigator:3.0:*:*:*:continuous_delivery:*:*:*

CNA Affected

[
  {
    "product": "Content Navigator",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "3.0CD"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.1%

Related for CVE-2019-4741