PT-2019-16941 · Ibm · Ibm Security Information Queue

Published

2019-06-06

·

Updated

2023-02-03

·

CVE-2019-4162

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Information Queue (ISIQ) versions 1.0.0 through 1.0.2
Description The issue arises from the missing HTTP Strict Transport Security header in the affected software. This allows users to potentially navigate to the unencrypted version of the web application or accept invalid certificates, resulting in sensitive data being sent unencrypted over the wire.
Recommendations For versions 1.0.0 through 1.0.2, consider implementing the HTTP Strict Transport Security header to enforce encrypted connections and prevent users from accessing the unencrypted version of the web application. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2019-4162

Affected Products

Ibm Security Information Queue