{"api_version":"1","generated_at":"2026-07-23T08:41:03+00:00","cve":"CVE-2019-4138","urls":{"html":"https://cve.report/CVE-2019-4138","api":"https://cve.report/api/cve/CVE-2019-4138.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4138","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4138"},"summary":{"title":"CVE-2019-4138","description":"IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 158334.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-05-29 15:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-522"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158334","name":"ibm-tivoli-cve20194138-info-disc (158334)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ibm.com/support/docview.wss?uid=ibm10880375","name":"http://www.ibm.com/support/docview.wss?uid=ibm10880375","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin:   Cross-site scripting and failure to enforce HTTP Strict Transport Security vulnerabilities in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) (CVE-2019-4137, CVE-2019-4138)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108533","name":"108533","refsource":"BID","tags":[],"title":"IBM Spectrum Control Cross Site Scripting and Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4138","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4138","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4138","vulnerable":"1","versionEndIncluding":"5.2.17.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4138","vulnerable":"1","versionEndIncluding":"5.3.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"version":{"version_data":[{"version_value":"5.2.13"},{"version_value":"5.2.14"},{"version_value":"5.2.15"},{"version_value":"5.2.16"},{"version_value":"5.2.15.2"},{"version_value":"5.2.17.0"},{"version_value":"5.2.17.1"},{"version_value":"5.2.17.2"},{"version_value":"5.3.0.1"},{"version_value":"5.3.15.3.2"}]},"product_name":"Spectrum Control Standard Edition"}]}}]}},"CVE_data_meta":{"DATE_PUBLIC":"2019-05-23T00:00:00","STATE":"PUBLIC","ID":"CVE-2019-4138","ASSIGNER":"psirt@us.ibm.com"},"problemtype":{"problemtype_data":[{"description":[{"value":"Obtain Information","lang":"eng"}]}]},"data_type":"CVE","data_version":"4.0","impact":{"cvssv3":{"BM":{"S":"U","UI":"N","C":"H","A":"N","I":"N","AC":"H","PR":"N","AV":"N","SCORE":"5.900"},"TM":{"E":"U","RC":"C","RL":"O"}}},"data_format":"MITRE","description":{"description_data":[{"value":"IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 158334.","lang":"eng"}]},"references":{"reference_data":[{"url":"http://www.ibm.com/support/docview.wss?uid=ibm10880375","refsource":"CONFIRM","name":"http://www.ibm.com/support/docview.wss?uid=ibm10880375","title":"IBM Security Bulletin 880375 (Spectrum Control Standard Edition)"},{"title":"X-Force Vulnerability Report","name":"ibm-tivoli-cve20194138-info-disc (158334)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158334"},{"refsource":"BID","name":"108533","url":"http://www.securityfocus.com/bid/108533"}]}},"nvd":{"publishedDate":"2019-05-29 15:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-522"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_control:*:*:*:*:*:*:*:*","versionStartIncluding":"5.3.0.0","versionEndIncluding":"5.3.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_control:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2.13.0","versionEndIncluding":"5.2.17.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4138","Ordinal":"141749","Title":"CVE-2019-4138","CVE":"CVE-2019-4138","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4138","Ordinal":"1","NoteData":"IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 158334.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4138","Ordinal":"2","NoteData":"2019-05-29","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4138","Ordinal":"3","NoteData":"2019-06-03","Type":"Other","Title":"Modified"}]}}}