CVE-2019-4427: IBM Cloud CLI

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Cloud CLI 0.6.0 through 0.16.1 windows installers are signed using SHA1 certificate. An attacker might be able to exploit the weak algorithm to generate a installer with malicious software inside. IBM X-Force ID: 162773.

Affected products

  • IBM Cloud CLI: from 0.6.0, up to and including 0.16.1

Published 2020-02-12. Last modified 2026-06-17.