CVE-2019-4162
Summary
| CVE | CVE-2019-4162 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-06 21:29:00 UTC |
| Updated | 2023-02-03 20:39:00 UTC |
| Description | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Security Information Queue | 1.0.0 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.1 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.2 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.0 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.1 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM Security Information Queue web server allows downgrading to non-secure HTTP | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.