Information Disclosure Vulnerability in IBM Security Information Queue
CVE-2020-4291
4.7MEDIUM
Summary
The IBM Security Information Queue is susceptible to information disclosure due to an insufficient timeout feature in its Web UI. This vulnerability allows unauthorized users to gain access to sensitive information, thereby posing a security risk to the integrity of data managed by the affected versions of the software. Organizations utilizing this product are advised to implement mitigations as soon as possible to protect their systems.
Affected Version(s)
Security Information Queue 1.0.0
Security Information Queue 1.0.1
Security Information Queue 1.0.2
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved