CVE-2019-4013 EXPLOIT
9.0
CRITICAL · CVSS 3.0 · EPSS 13% (pctl 96)
Patch early
A public exploit exists.
Description
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
Scoring
| CVSS | 9.0 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
| EPSS | 13% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | bigfix platform |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Bigfix Platform 9.5.9.62 - Arbitrary File Upload | 2019-10-07 |
References
- http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html
- http://www.ibm.com/support/docview.wss?uid=ibm10874666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155887
- http://packetstormsecurity.com/files/154747/IBM-Bigfix-Platform-9.5.9.62-Arbitary-File-Upload-Code-Execution.html
- http://www.ibm.com/support/docview.wss?uid=ibm10874666
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155887
→ the Explorer · watch your stack · NVD