{"api_version":"1","generated_at":"2026-07-23T12:04:03+00:00","cve":"CVE-2019-4162","urls":{"html":"https://cve.report/CVE-2019-4162","api":"https://cve.report/api/cve/CVE-2019-4162.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4162","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4162"},"summary":{"title":"CVE-2019-4162","description":"IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-06-06 21:29:00","updated_at":"2023-02-03 20:39:00"},"problem_types":["CWE-319"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/docview.wss?uid=ibm10885963","name":"https://www.ibm.com/support/docview.wss?uid=ibm10885963","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security Bulletin: IBM Security Information Queue web server allows downgrading to non-secure HTTP","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158661","name":"ibm-isiq-cve20194162-info-disc (158661)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4162","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4162","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4162","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"security_information_queue","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"description":{"description_data":[{"value":"IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.","lang":"eng"}]},"data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-4162","ASSIGNER":"psirt@us.ibm.com","DATE_PUBLIC":"2019-06-04T00:00:00","STATE":"PUBLIC"},"data_format":"MITRE","impact":{"cvssv3":{"BM":{"SCORE":"5.900","I":"N","PR":"N","AC":"H","AV":"N","S":"U","UI":"N","A":"N","C":"H"},"TM":{"RL":"O","E":"U","RC":"C"}}},"problemtype":{"problemtype_data":[{"description":[{"value":"Obtain Information","lang":"eng"}]}]},"data_type":"CVE","affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Security Information Queue","version":{"version_data":[{"version_value":"1.0.0"},{"version_value":"1.0.1"},{"version_value":"1.0.2"}]}}]}}]}},"references":{"reference_data":[{"title":"IBM Security Bulletin 885963 (Security Information Queue)","refsource":"CONFIRM","name":"https://www.ibm.com/support/docview.wss?uid=ibm10885963","url":"https://www.ibm.com/support/docview.wss?uid=ibm10885963"},{"title":"X-Force Vulnerability Report","refsource":"XF","name":"ibm-isiq-cve20194162-info-disc (158661)","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/158661"}]}},"nvd":{"publishedDate":"2019-06-06 21:29:00","lastModifiedDate":"2023-02-03 20:39:00","problem_types":["CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:security_information_queue:1.0.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:security_information_queue:1.0.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:security_information_queue:1.0.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4162","Ordinal":"141773","Title":"CVE-2019-4162","CVE":"CVE-2019-4162","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4162","Ordinal":"1","NoteData":"IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4162","Ordinal":"2","NoteData":"2019-06-06","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4162","Ordinal":"3","NoteData":"2019-06-06","Type":"Other","Title":"Modified"}]}}}