← Back to browse · API

CVE-2019-4279

Severity
CRITICAL
CVSS
9.0
EPSS
0.79926
Risk score
63.97
CISA KEV
No
PoC
No
Published
2019-05-17
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2019-13886, GHSA-86JP-P2QR-PC2R
Products
IBM:WebSphere Application Server 8.5, IBM:WebSphere Application Server 9.0
Sources
euvd EUVD-2019-13886

Description

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 160445.

References