CVE-2020-4290

CWE-2903 documents3 sources
Severity
5.4MEDIUM
EPSS
0.1%
top 71.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateMay 24

Description

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5ibm/security_information_queue6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j2rq-9729-p9fr: IBM Security Information Queue (ISIQ) 12022-05-24
CVEList
CVE-2020-4290: IBM Security Information Queue (ISIQ) 12020-04-08