PT-2019-16941 · Ibm · Ibm Security Information Queue
Published
2019-06-06
·
Updated
2023-02-03
·
CVE-2019-4162
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Security Information Queue (ISIQ) versions 1.0.0 through 1.0.2
Description
The issue arises from the missing HTTP Strict Transport Security header in the affected software. This allows users to potentially navigate to the unencrypted version of the web application or accept invalid certificates, resulting in sensitive data being sent unencrypted over the wire.
Recommendations
For versions 1.0.0 through 1.0.2, consider implementing the HTTP Strict Transport Security header to enforce encrypted connections and prevent users from accessing the unencrypted version of the web application.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Security Information Queue