CVE-2019-4732 describes a DLL search order hijacking vulnerability in IBM SDK, Java Technology Edition versions 7.0, 7.1, and 8.0, affecting IBM and Microsoft products running on Windows. This flaw allows a local, authenticated attacker to execute arbitrary code by placing a specially crafted file in a compromised folder. The vulnerability has a CVSSv3.1 score of 6.5 (Medium), indicating high impact on confidentiality, integrity, and availability, with low attack complexity and requiring user interaction. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0.0, <= 7.0.10.55CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:*:*:*:java_technology:*:*:* | ||
>= 7.1.0.0, <= 7.1.4.55CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:*:*:*:java_technology:*:*:* | ||
>= 8.0.0.0, <= 8.0.6.0CPE matchmatch criteria | cpe:2.3:a:ibm:sdk:*:*:*:*:java_technology:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:ibm:websphere_application_server:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.