Vulnerability Details CVE-2019-4162
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 is missing the HTTP Strict Transport Security header. Users can navigate by mistake to the unencrypted version of the web application or accept invalid certificates. This leads to sensitive data being sent unencrypted over the wire. IBM X-Force ID: 158661.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 18.9%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 5.0
Products affected by CVE-2019-4162
-
cpe:2.3:a:ibm:security_information_queue:1.0.0
-
cpe:2.3:a:ibm:security_information_queue:1.0.1
-
cpe:2.3:a:ibm:security_information_queue:1.0.2