{"api_version":"1","generated_at":"2026-07-23T13:18:08+00:00","cve":"CVE-2019-4741","urls":{"html":"https://cve.report/CVE-2019-4741","api":"https://cve.report/api/cve/CVE-2019-4741.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4741","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4741"},"summary":{"title":"CVE-2019-4741","description":"IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2020-02-12 16:15:00","updated_at":"2020-02-14 18:58:00"},"problem_types":["CWE-918"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/172815","name":"ibm-cn-cve20194741-ssrf (172815)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.ibm.com/support/pages/node/1846569","name":"https://www.ibm.com/support/pages/node/1846569","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: IBM Content Navigator is vulnerable to Server Side Request Forgery (SSRF)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4741","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4741","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4741","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"content_navigator","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"continuous_delivery","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"content_navigator","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"continuous_delivery","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4741","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_version":"4.0","problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Gain Access"}]}]},"CVE_data_meta":{"STATE":"PUBLIC","DATE_PUBLIC":"2020-02-10T00:00:00","ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2019-4741"},"references":{"reference_data":[{"name":"https://www.ibm.com/support/pages/node/1846569","title":"IBM Security Bulletin 1846569 (Content Navigator)","refsource":"CONFIRM","url":"https://www.ibm.com/support/pages/node/1846569"},{"name":"ibm-cn-cve20194741-ssrf (172815)","title":"X-Force Vulnerability Report","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/172815","refsource":"XF"}]},"impact":{"cvssv3":{"BM":{"I":"L","C":"N","AV":"N","A":"N","S":"U","PR":"N","UI":"N","SCORE":"5.300","AC":"L"},"TM":{"RC":"C","E":"U","RL":"O"}}},"data_format":"MITRE","description":{"description_data":[{"lang":"eng","value":"IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815."}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Content Navigator","version":{"version_data":[{"version_value":"3.0CD"}]}}]},"vendor_name":"IBM"}]}}},"nvd":{"publishedDate":"2020-02-12 16:15:00","lastModifiedDate":"2020-02-14 18:58:00","problem_types":["CWE-918"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:content_navigator:3.0.0:*:*:*:continuous_delivery:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4741","Ordinal":"142352","Title":"CVE-2019-4741","CVE":"CVE-2019-4741","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4741","Ordinal":"1","NoteData":"IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 172815.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4741","Ordinal":"2","NoteData":"2020-02-12","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4741","Ordinal":"3","NoteData":"2020-02-12","Type":"Other","Title":"Modified"}]}}}