Unauthorized Action Bypass in IBM Security Information Queue
CVE-2020-4282

3LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 April 2020

Summary

IBM Security Information Queue allows authenticated users to exploit improper character validation, thereby enabling unauthorized actions within the application. Multiple versions of the product are susceptible to this security flaw, which could lead to significant data integrity issues if left unaddressed. For further information, visit the IBM support page and X-Force Exchange.

Affected Version(s)

Security Information Queue 1.0.0

Security Information Queue 1.0.1

Security Information Queue 1.0.2

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.