CVE-2019-4038: IBM Security Identity Manager

Medium severity, CVSS 6.2. EPSS: 0.4% chance of exploitation in the next 30 days.

IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code injection. IBM X-Force ID: 156162.

Affected products

  • IBM Security Identity Manager: from 6.0.0.0, up to and including 6.0.0.20; from 7.0.0.0, up to and including 7.0.1.10

Published 2019-02-04. Last modified 2026-06-17.