CVE-2020-4290

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:security_information_queue:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_information_queue:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_information_queue:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_information_queue:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_information_queue:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:security_information_queue:1.0.5:*:*:*:*:*:*:*

History

21 Nov 2024, 05:32

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/176333 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/176333 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6172599 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/6172599 - Patch, Vendor Advisory

Information

Published : 2020-04-08 14:15

Updated : 2024-11-21 05:32


NVD link : CVE-2020-4290

Mitre link : CVE-2020-4290

CVE.ORG link : CVE-2020-4290


JSON object : View

Products Affected

ibm

  • security_information_queue
CWE
CWE-290

Authentication Bypass by Spoofing