{"api_version":"1","generated_at":"2026-07-23T08:55:32+00:00","cve":"CVE-2019-4259","urls":{"html":"https://cve.report/CVE-2019-4259","api":"https://cve.report/api/cve/CVE-2019-4259.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4259","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4259"},"summary":{"title":"CVE-2019-4259","description":"A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-05-13 16:29:00","updated_at":"2023-01-30 19:10:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/160011","name":"ibm-spectrum-cve20194259-info-disc (160011)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/docview.wss?uid=ibm10883568","name":"https://www.ibm.com/support/docview.wss?uid=ibm10883568","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"IBM Security Bulletin: A vulnerability has been identified in IBM Spectrum Scale with CES stack enabled that could allow sensitive data to be included with service snaps.  This data could be sent to IBM during service engagements (CVE-2019-4259)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4259","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4259","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4259","vulnerable":"1","versionEndIncluding":"4.1.1.22","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_scale","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4259","vulnerable":"1","versionEndIncluding":"4.2.3.13","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_scale","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4259","vulnerable":"1","versionEndIncluding":"5.0.2.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"spectrum_scale","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"impact":{"cvssv3":{"BM":{"I":"N","C":"L","S":"U","SCORE":"4.000","A":"N","AC":"L","PR":"N","UI":"N","AV":"L"},"TM":{"RC":"C","RL":"O","E":"U"}}},"description":{"description_data":[{"lang":"eng","value":"A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011."}]},"references":{"reference_data":[{"name":"https://www.ibm.com/support/docview.wss?uid=ibm10883568","title":"IBM Security Bulletin 883568 (Spectrum Scale)","url":"https://www.ibm.com/support/docview.wss?uid=ibm10883568","refsource":"CONFIRM"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/160011","refsource":"XF","name":"ibm-spectrum-cve20194259-info-disc (160011)","title":"X-Force Vulnerability Report"}]},"data_version":"4.0","problemtype":{"problemtype_data":[{"description":[{"value":"Obtain Information","lang":"eng"}]}]},"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2019-4259","DATE_PUBLIC":"2019-05-10T00:00:00","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Spectrum Scale","version":{"version_data":[{"version_value":"4.1.1"},{"version_value":"4.2.0"},{"version_value":"4.2.1"},{"version_value":"4.2.2"},{"version_value":"4.2.3"},{"version_value":"5.0.0"}]}}]}}]}}},"nvd":{"publishedDate":"2019-05-13 16:29:00","lastModifiedDate":"2023-01-30 19:10:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_scale:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.1.0","versionEndIncluding":"4.1.1.22","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_scale:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2.0.0","versionEndIncluding":"4.2.3.13","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:spectrum_scale:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0.0.0","versionEndIncluding":"5.0.2.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4259","Ordinal":"141870","Title":"CVE-2019-4259","CVE":"CVE-2019-4259","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4259","Ordinal":"1","NoteData":"A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES stack enabled that could allow sensitive data to be included with service snaps. IBM X-Force ID: 160011.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4259","Ordinal":"2","NoteData":"2019-05-13","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4259","Ordinal":"3","NoteData":"2019-05-13","Type":"Other","Title":"Modified"}]}}}