CVE-2020-4290
MEDIUMIBM Security Information Queue 1.0.0-1.0.5 - Authenticated Configuration Owner Spoofing
Title source: llmDescription
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.
References (2)
Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/pages/node/6172599
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/176333
Scores
CVSS v3
5.4
EPSS
0.0067
EPSS Percentile
47.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-290
Status
published
Products (6)
ibm/security_information_queue
1.0.0
ibm/security_information_queue
1.0.1
ibm/security_information_queue
1.0.2
ibm/security_information_queue
1.0.3
ibm/security_information_queue
1.0.4
ibm/security_information_queue
1.0.5
Published
Apr 08, 2020
Tracked Since
Feb 18, 2026