PT-2020-17979 · Ibm · Ibm Security Information Queue

Chris Shepherd

+7

·

Published

2020-03-02

·

Updated

2021-07-21

·

CVE-2020-4292

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Security Information Queue (ISIQ) versions 1.0.0 through 1.0.4
Description The issue concerns a cross-domain policy file that includes untrusted domains, potentially leading to the disclosure of sensitive information.
Recommendations For IBM Security Information Queue (ISIQ) versions 1.0.0 through 1.0.4, consider restricting access to the cross-domain policy file to minimize the risk of sensitive information disclosure until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-4292

Affected Products

Ibm Security Information Queue