Authentication Bypass by Spoofing in IBM Security Verify Information Queue - CVE-2020-4290
Published: June 2, 2023
Vulnerability identifier: #VU76811
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4290
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access.
The vulnerability exists due to spoof the configuration owner. A remote user can spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access.
Affected software
IBM Security Verify Information Queue
How to mitigate CVE-2020-4290
Install updates from vendor's website.
IBM Security Verify Information Queue - update to 1.0.6