IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.
References
Link | Resource |
---|---|
https://www.ibm.com/support/docview.wss?uid=ibm10885963 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/158661 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-06 14:29
Updated : 2023-02-03 12:39
NVD link : CVE-2019-4162
Mitre link : CVE-2019-4162
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
ibm
- security_information_queue