Critical severity9.8NVD Advisory· Published Apr 15, 2019· Updated Jun 17, 2026
CVE-2019-4012
CVE-2019-4012
Description
IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 155886.
Affected products
6cpe:2.3:a:ibm:bigfix_webui_profile_management:6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:bigfix_webui_profile_management:6:*:*:*:*:*:*:*
- (no CPE)range: 6
- cpe:2.3:a:ibm:bigfix_webui_software_distribution:23:*:*:*:*:*:*:*
- IBM/BigFix WebUI Profile Managementv5Range: 6
- IBM/BigFix WebUI Software Distributionv5Range: 23
- Range: 23
Patches
Vulnerability mechanics
References
3- www.ibm.com/support/docview.wssnvdVendor Advisory
- www.securityfocus.com/bid/108038nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/155886nvdVDB EntryVendor Advisory
News mentions
0No linked articles in our index yet.