| |
Vulnerability CVE-2020-4290
Published: 2020-04-08
Description: |
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333. |
Type:
CWE-290 (Authentication Bypass by Spoofing)
CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
5.5/10 |
4.9/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Partial |
Partial |
None |
References: |
https://exchange.xforce.ibmcloud.com/vulnerabilities/176333
https://www.ibm.com/support/pages/node/6172599
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|