{"api_version":"1","generated_at":"2026-04-23T15:41:38+00:00","cve":"CVE-2019-4592","urls":{"html":"https://cve.report/CVE-2019-4592","api":"https://cve.report/api/cve/CVE-2019-4592.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4592","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4592"},"summary":{"title":"CVE-2019-4592","description":"IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server. IBM X-Force ID: 167647.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-02-13 16:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/167647","name":"ibm-tivoli-cve20194592-dos (167647)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/2278617","name":"https://www.ibm.com/support/pages/node/2278617","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: Authentication bypass in IBM Tivoli Monitoring Service console","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4592","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4592","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4592","vulnerable":"1","versionEndIncluding":"6.3.0.7.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_monitoring","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Denial of Service"}]}]},"CVE_data_meta":{"DATE_PUBLIC":"2020-02-12T00:00:00","ID":"CVE-2019-4592","STATE":"PUBLIC","ASSIGNER":"psirt@us.ibm.com"},"data_type":"CVE","affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Tivoli Monitoring","version":{"version_data":[{"version_value":"6.3.0.7.3"},{"version_value":"6.3.0.7.10"}]}}]}}]}},"references":{"reference_data":[{"refsource":"CONFIRM","url":"https://www.ibm.com/support/pages/node/2278617","title":"IBM Security Bulletin 2278617 (Tivoli Monitoring)","name":"https://www.ibm.com/support/pages/node/2278617"},{"refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/167647","name":"ibm-tivoli-cve20194592-dos (167647)","title":"X-Force Vulnerability Report"}]},"impact":{"cvssv3":{"BM":{"A":"H","AV":"N","SCORE":"7.500","C":"N","S":"U","AC":"L","I":"N","UI":"N","PR":"N"},"TM":{"RL":"O","E":"U","RC":"C"}}},"data_format":"MITRE","description":{"description_data":[{"value":"IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server. IBM X-Force ID: 167647.","lang":"eng"}]}},"nvd":{"publishedDate":"2020-02-13 16:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:tivoli_monitoring:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3.0.7.3","versionEndIncluding":"6.3.0.7.10","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4592","Ordinal":"142203","Title":"CVE-2019-4592","CVE":"CVE-2019-4592","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4592","Ordinal":"1","NoteData":"IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server. IBM X-Force ID: 167647.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4592","Ordinal":"2","NoteData":"2020-02-13","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4592","Ordinal":"3","NoteData":"2020-02-13","Type":"Other","Title":"Modified"}]}}}