CVE-2019-4219Information Exposure via Error Message in IBM Security Information Queue

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 68.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 6
Latest updateMay 24

Description

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 159228.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/security_information_queue1.0.0, 1.0.1, 1.0.2+2
NVDibm/security_information_queue1.0.0, 1.0.1, 1.0.2+2

🔴Vulnerability Details

2
GHSA
GHSA-c258-x2h2-fqhc: IBM Security Information Queue (ISIQ) 12022-05-24
CVEList
CVE-2019-4219: IBM Security Information Queue (ISIQ) 12019-06-06
CVE-2019-4219 — Information Exposure via Error Message | cvebase