CVE-2020-4290
Summary
| CVE | CVE-2020-4290 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-08 14:15:00 UTC |
| Updated | 2020-04-08 18:22:00 UTC |
| Description | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333. |
Risk And Classification
Problem Types: CWE-290
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Security Information Queue | 1.0.0 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.1 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.2 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.3 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.4 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.5 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.0 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.1 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.2 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.3 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.4 | All | All | All |
| Application | Ibm | Security Information Queue | 1.0.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM Security Information Queue does not prevent a product's owner from being modified (CVE-2020-4290) | CONFIRM | www.ibm.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | VDB Entry, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.