Authentication Bypass by Spoofing in IBM Security Verify Information Queue - CVE-2020-4290

 

Authentication Bypass by Spoofing in IBM Security Verify Information Queue - CVE-2020-4290

Published: June 2, 2023


Vulnerability identifier: #VU76811
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-4290
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access.

The vulnerability exists due to spoof the configuration owner. A remote user can spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access.


Affected software

IBM Security Verify Information Queue

How to mitigate CVE-2020-4290

Install updates from vendor's website.

IBM Security Verify Information Queue - update to 1.0.6

External References

Related Security Bulletins