{"api_version":"1","generated_at":"2026-07-23T08:17:46+00:00","cve":"CVE-2019-4640","urls":{"html":"https://cve.report/CVE-2019-4640","api":"https://cve.report/api/cve/CVE-2019-4640.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4640","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4640"},"summary":{"title":"CVE-2019-4640","description":"IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-02-19 16:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-346"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/pages/node/2929923","name":"https://www.ibm.com/support/pages/node/2929923","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: A Security Vulnerability Has Been Identified In IBM Security Secret Server (CVE-2019-4640)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/170046","name":"ibm-sss-cve20194640-code-exec (170046)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4640","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4640","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4640","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_secret_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4640","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_secret_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4640","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4640","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2019-4640","STATE":"PUBLIC","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2020-02-18T00:00:00"},"data_type":"CVE","description":{"description_data":[{"lang":"eng","value":"IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046."}]},"impact":{"cvssv3":{"BM":{"PR":"H","A":"N","S":"U","UI":"N","C":"N","AC":"H","SCORE":"4.400","AV":"N","I":"H"},"TM":{"E":"U","RC":"C","RL":"O"}}},"problemtype":{"problemtype_data":[{"description":[{"value":"Gain Access","lang":"eng"}]}]},"data_format":"MITRE","data_version":"4.0","affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"version":{"version_data":[{"version_value":"10.7"}]},"product_name":"Security Secret Server"}]}}]}},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/2929923","url":"https://www.ibm.com/support/pages/node/2929923","title":"IBM Security Bulletin 2929923 (Security Secret Server)","refsource":"CONFIRM"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/170046","name":"ibm-sss-cve20194640-code-exec (170046)","refsource":"XF","title":"X-Force Vulnerability Report"}]}},"nvd":{"publishedDate":"2020-02-19 16:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-346"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:security_secret_server:*:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4640","Ordinal":"142251","Title":"CVE-2019-4640","CVE":"CVE-2019-4640","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4640","Ordinal":"1","NoteData":"IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4640","Ordinal":"2","NoteData":"2020-02-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4640","Ordinal":"3","NoteData":"2020-02-19","Type":"Other","Title":"Modified"}]}}}