← back
CVE-2019-4202critical

CVE-2019-4202

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 4.2%
exploitation probability
4.2%top 9% of all CVEs
observed exploitation
nono source reports it
IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially crafted request can run arbitrary code on the server and gain complete access to the system. IBM X-Force ID: 159123.
CVSS:3.0/C:H/I:H/AC:L/UI:N/AV:N/S:C/A:H/PR:N/RL:O/E:U/RC:C
Affected products
IBM · API Connect