Vulnerability Description
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Security Information Queue | 1.0.0 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/158661VDB EntryVendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10885963PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/158661VDB EntryVendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10885963PatchVendor Advisory
FAQ
What is CVE-2019-4162?
CVE-2019-4162 is a vulnerability with a CVSS score of 7.5 (HIGH). IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or a...
How severe is CVE-2019-4162?
CVE-2019-4162 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-4162?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Information Queue.