{"api_version":"1","generated_at":"2026-07-23T12:06:15+00:00","cve":"CVE-2019-4457","urls":{"html":"https://cve.report/CVE-2019-4457","api":"https://cve.report/api/cve/CVE-2019-4457.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4457","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4457"},"summary":{"title":"CVE-2019-4457","description":"IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 163654.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-02-19 16:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163654","name":"ibm-jazz-cve20194457-info-disc (163654)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/2867997","name":"https://www.ibm.com/support/pages/node/2867997","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Security vulnerabilities affect multiple IBM Rational products based on IBM Jazz technology","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4457","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4457","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4457","vulnerable":"1","versionEndIncluding":"6.0.6.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"jazz_foundation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"version":{"version_data":[{"version_value":"6.0"},{"version_value":"6.0.1"},{"version_value":"6.0.2"},{"version_value":"6.0.3"},{"version_value":"6.0.4"},{"version_value":"6.0.5"},{"version_value":"6.0.6"},{"version_value":"6.0.6.1"}]},"product_name":"Rational Rhapsody Design Manager"}]},"vendor_name":"IBM"}]}},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/2867997","url":"https://www.ibm.com/support/pages/node/2867997","refsource":"CONFIRM","title":"IBM Security Bulletin 2867997 (Rational Rhapsody Design Manager)"},{"refsource":"XF","title":"X-Force Vulnerability Report","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163654","name":"ibm-jazz-cve20194457-info-disc (163654)"}]},"impact":{"cvssv3":{"TM":{"E":"U","RC":"C","RL":"O"},"BM":{"A":"N","PR":"L","AC":"L","C":"L","S":"U","UI":"N","AV":"N","SCORE":"4.300","I":"N"}}},"CVE_data_meta":{"ID":"CVE-2019-4457","DATE_PUBLIC":"2020-02-18T00:00:00","ASSIGNER":"psirt@us.ibm.com","STATE":"PUBLIC"},"data_type":"CVE","description":{"description_data":[{"lang":"eng","value":"IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 163654."}]},"data_version":"4.0","problemtype":{"problemtype_data":[{"description":[{"value":"Obtain Information","lang":"eng"}]}]},"data_format":"MITRE"},"nvd":{"publishedDate":"2020-02-19 16:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:jazz_foundation:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.6.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4457","Ordinal":"142068","Title":"CVE-2019-4457","CVE":"CVE-2019-4457","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4457","Ordinal":"1","NoteData":"IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obtain sensitive information that could be used in further attacks against the system. IBM X-Force ID: 163654.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4457","Ordinal":"2","NoteData":"2020-02-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4457","Ordinal":"3","NoteData":"2020-02-19","Type":"Other","Title":"Modified"}]}}}