VYPR
Unrated severityNVD Advisory· Published Jun 6, 2019· Updated Sep 17, 2024

CVE-2019-4161

CVE-2019-4161

Description

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 158660.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Information Queue (ISIQ) versions 1.0.0-1.0.2 expose internal development data, aiding further attacks.

Vulnerability

IBM Security Information Queue (ISIQ) versions 1.0.0, 1.0.1, and 1.0.2 disclose internal data left over from the product development and Beta phases [1]. This data includes information such as the exact HTTP server level, which is not intended for production environments. The vulnerability is present in the default configuration and does not require any special conditions to be reachable.

Exploitation

An attacker with local network access to an ISIQ instance can retrieve the exposed internal data without authentication [1]. The data is accessible through normal HTTP requests to the service, as the development artifacts were not removed from the production images dropped into Docker Hub.

Impact

Successful exploitation allows an attacker to obtain sensitive information about the system, such as the exact HTTP server level [1]. While much of the data is specific to ISIQ's development environment, the disclosed information can be used to mount further attacks on the system. The CVSS vector indicates a low confidentiality impact (C:L) with no impact on integrity or availability [1].

Mitigation

IBM released ISIQ version 1.0.3 which removes the internal data [1]. Users should upgrade to version 1.0.3 or later from the Docker Hub repository ibmcorp/security_information_queue [1]. No workarounds are documented; upgrading is the recommended action.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.