CVE-2019-4732

Description

IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client. By placing a specially-crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 172618.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.164

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.4.2Windows
Multiple Vulnerabilities are affected in IBM Business Automation Workflow 19.0.0.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.10Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.7Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.8Windows
Multiple Vulnerabilities are affected in IBM Operational Decision Manager 8.9Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.0Windows
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.7Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.2.0.2Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 8.1.0.2Windows
Multiple Vulnerabilities are affected in IBM Spectrum Protect Server 7.1.10Windows
Multiple Vulnerabilities are affected in IBM Spectrum Protect Server 8.1.9Windows
Multiple Vulnerabilities are affected in IBM TXSeries for Multiplatforms 9.1.0.0Windows
SUSE-SU-2020:0528-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-1.8.0_sr6.5-30.63.1.x86_64.rpmLinux
SUSE-SU-2020:0528-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-alsa-1.8.0_sr6.5-30.63.1.x86_64.rpmLinux
SUSE-SU-2020:0528-1(SUSE Linux Enterprise Server 12-SP5) java-1_8_0-ibm-plugin-1.8.0_sr6.5-30.63.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234