PT-2020-10960 · Ibm · Ibm Security Directory Server

Published

2020-02-04

·

Updated

2021-07-21

·

CVE-2019-4541

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Security Directory Server version 6.4.0
Description The issue is related to incomplete blacklisting for input validation, allowing attackers to bypass application controls. This results in a direct impact to the system and data integrity.
Recommendations For IBM Security Directory Server version 6.4.0, consider implementing additional input validation mechanisms to prevent attackers from bypassing application controls until a patch is available. As a temporary workaround, review and enhance the existing blacklisting configuration to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-4541

Affected Products

Ibm Security Directory Server