{"api_version":"1","generated_at":"2026-07-23T08:34:32+00:00","cve":"CVE-2019-4103","urls":{"html":"https://cve.report/CVE-2019-4103","api":"https://cve.report/api/cve/CVE-2019-4103.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4103","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4103"},"summary":{"title":"CVE-2019-4103","description":"IBM Tivoli Netcool/Impact 7.1.0 allows for remote execution of command by low privileged User. Remote code execution allow to execute arbitrary code on system which lead to take control over the system. IBM X-Force ID: 158094.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-06-17 15:15:00","updated_at":"2023-02-03 18:49:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/docview.wss?uid=ibm10887523","name":"https://www.ibm.com/support/docview.wss?uid=ibm10887523","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: IBM Tivoli Netcool Impact Remote Code Execution (CVE-2019-4103)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158094","name":"ibm-netcool-cve20194103-code-exec (158094)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4103","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4103","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4103","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_netcool/impact","cpe6":"7.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4103","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_netcool\\/impact","cpe6":"7.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4103","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_netcool\\/impact","cpe6":"7.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_format":"MITRE","references":{"reference_data":[{"refsource":"CONFIRM","url":"https://www.ibm.com/support/docview.wss?uid=ibm10887523","title":"IBM Security Bulletin 887523 (Tivoli Netcool/Impact)","name":"https://www.ibm.com/support/docview.wss?uid=ibm10887523"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158094","refsource":"XF","name":"ibm-netcool-cve20194103-code-exec (158094)","title":"X-Force Vulnerability Report"}]},"data_version":"4.0","impact":{"cvssv3":{"BM":{"C":"H","AV":"A","S":"U","AC":"L","PR":"L","UI":"N","I":"H","SCORE":"8.000","A":"H"},"TM":{"RC":"C","RL":"O","E":"U"}}},"CVE_data_meta":{"ID":"CVE-2019-4103","STATE":"PUBLIC","DATE_PUBLIC":"2019-06-14T00:00:00","ASSIGNER":"psirt@us.ibm.com"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"version":{"version_data":[{"version_value":"7.1.0"}]},"product_name":"Tivoli Netcool/Impact"}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"value":"Gain Access","lang":"eng"}]}]},"description":{"description_data":[{"lang":"eng","value":"IBM Tivoli Netcool/Impact 7.1.0 allows for remote execution of command by low privileged User. Remote code execution allow to execute arbitrary code on system which lead to take control over the system. IBM X-Force ID: 158094."}]},"data_type":"CVE"},"nvd":{"publishedDate":"2019-06-17 15:15:00","lastModifiedDate":"2023-02-03 18:49:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:L/Au:S/C:C/I:C/A:C","accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.7},"severity":"HIGH","exploitabilityScore":5.1,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:tivoli_netcool\\/impact:7.1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4103","Ordinal":"141714","Title":"CVE-2019-4103","CVE":"CVE-2019-4103","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4103","Ordinal":"1","NoteData":"IBM Tivoli Netcool/Impact 7.1.0 allows for remote execution of command by low privileged User. Remote code execution allow to execute arbitrary code on system which lead to take control over the system. IBM X-Force ID: 158094.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4103","Ordinal":"2","NoteData":"2019-06-17","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4103","Ordinal":"3","NoteData":"2019-06-17","Type":"Other","Title":"Modified"}]}}}