CVE-2019-4433
Status: ModifiedHigh (8.2)—
IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162890.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
- Base score: 8.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.85%
- Percentile among all scored CVEs: 90
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-611
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162890
- https://www.ibm.com/support/docview.wss?uid=ibm10958079
- https://www.ibm.com/support/docview.wss?uid=ibm10958081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/162890
- https://www.ibm.com/support/docview.wss?uid=ibm10958079
- https://www.ibm.com/support/docview.wss?uid=ibm10958081
Raw JSON (NVD)
Show
{
"id": "CVE-2019-4433",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "psirt@us.ibm.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.8
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "psirt@us.ibm.com",
"affectedData": [
{
"vendor": "IBM",
"product": "InfoSphere Identity Insight",
"versions": [
{
"status": "affected",
"version": "8.1"
},
{
"status": "affected",
"version": "9.0"
}
]
},
{
"vendor": "IBM",
"product": "InfoSphere Global Name Management",
"versions": [
{
"status": "affected",
"version": "5.0"
},
{
"status": "affected",
"version": "6.0"
}
]
}
]
}
],
"published": "2019-08-20T19:15:16.793",
"references": [
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/162890",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10958079",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10958081",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "psirt@us.ibm.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/162890",
"tags": [
"Broken Link",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10958079",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.ibm.com/support/docview.wss?uid=ibm10958081",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-611"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162890."
},
{
"lang": "es",
"value": "IBM InfoSphere Global Name Management 5.0 y 6.0 e IBM InfoSphere Identity Insight 8.1 y 9.0 son vulnerables a un ataque de inyección de entidades externas XML (XXE) al procesar datos XML. Un atacante remoto podría aprovechar esta vulnerabilidad para exponer información confidencial o consumir recursos de memoria. ID de IBM X-Force: 162890."
}
],
"lastModified": "2026-06-17T02:36:31.730",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:infosphere_global_name_management:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D350D86F-C1CF-4827-8B17-B4858C6C6AD1"
},
{
"criteria": "cpe:2.3:a:ibm:infosphere_global_name_management:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5BA4B7E-017A-4E4C-86F6-67C5ED6293E3"
},
{
"criteria": "cpe:2.3:a:ibm:infosphere_identity_insight:8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01DA4DEF-B2F9-4441-B40A-626A0DB72847"
},
{
"criteria": "cpe:2.3:a:ibm:infosphere_identity_insight:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9880D630-57BC-41A7-9A90-46DC7BA7721D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "psirt@us.ibm.com"
}