IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.
References
Link | Resource |
---|---|
https://www.ibm.com/support/pages/node/6172599 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/176333 | VDB Entry Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-04-08 07:15
Updated : 2020-04-08 11:22
NVD link : CVE-2020-4290
Mitre link : CVE-2020-4290
JSON object : View
CWE
CWE-290
Authentication Bypass by Spoofing
Products Affected
ibm
- security_information_queue