← Vulnerability feed

Vulnerability record · CVE-2019-4473 · published 5 August 2019

CVE-2019-4473: Ibm java uncontrolled search path element vulnerability

Ibm · Java

Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.

7.8 CVSS 3.1 High EPSS 0.45% · top 63.4% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score, v2 4.6
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-4473 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-0485Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and…EPSS 2.4%9.8CVE-2015-0192Ibm java improper privilege management vulnerabilityUnspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…EPSS 4.0%9.3CVE-2013-5456Ibm java vulnerabilityThe com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and…EPSS 6.0%9.3CVE-2013-5457Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code…EPSS 6.1%9.3CVE-2013-5458Ibm java vulnerabilityUnspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.4%9.3CVE-2013-3006Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%9.3CVE-2013-3007Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affe…EPSS 4.0%9.3CVE-2013-3008Ibm java vulnerabilityUnspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availab…EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2019-4473), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.