CVE-2019-4294 vulnerability in IBM Products
Published on August 20, 2019
IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. IBM X-Force ID: 16188.
Products Associated with CVE-2019-4294
stack.watch emails you whenever new vulnerabilities are published in IBM Datapower Gateway or IBM Mq Appliance. Just hit a watch button to start following.
Affected Versions
IBM MQ Appliance:- Version 8.0.0.3 is affected.
- Version 8.0.0.4 is affected.
- Version 8.0.0.5 is affected.
- Version 8.0.0.6 is affected.
- Version 8.0.0.0 is affected.
- Version 8.0.0.8 is affected.
- Version 8.0.0.10 is affected.
- Version 9.1.0.0 is affected.
- Version 8.0.0.11 is affected.
- Version 9.1.0.1 is affected.
- Version 9.1.1 is affected.
- Version 8.0.0.1 is affected.
- Version 8.0.0.7 is affected.
- Version 8.0.0.9 is affected.
- Version 8.0.0.2 is affected.
- Version 8.0.0.12 is affected.
- Version 9.1.0.2 is affected.
- Version 9.1.2 is affected.
- Version 7.6.0.0 is affected.
- Version 2018.4.1.0 is affected.
- Version 2018.4.1.6 is affected.
- Version 7.6.0.15 is affected.
- Version CD is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.