VYPR
Unrated severityNVD Advisory· Published Jun 6, 2019· Updated Sep 17, 2024

CVE-2019-4217

CVE-2019-4217

Description

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159226.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM Security Information Queue versions 1.0.0–1.0.2 are vulnerable to clickjacking, allowing a remote attacker to hijack user click actions via a malicious website.

Vulnerability

IBM Security Information Queue (ISIQ) versions 1.0.0, 1.0.1, and 1.0.2 are vulnerable to clickjacking. The web application fails to set proper X-Frame-Options headers or use frame-busting scripts, allowing an attacker to embed the ISIQ interface into a malicious frame or object. This affects all deployments of the affected versions, regardless of configuration [1].

Exploitation

An attacker must host a malicious website that embeds the legitimate ISIQ page in a transparent or hidden iframe and trick a victim into visiting that site (e.g., via phishing). The victim must be logged into ISIQ at the time. No authentication on the attacker's part is needed beyond crafting the malicious page. The attacker can then overlay deceptive UI elements to hijack the victim's clicks on the hidden ISIQ page, potentially triggering actions the victim did not intend [1].

Impact

Successful exploitation results in the attacker being able to hijack click actions performed by the victim within the context of the ISIQ session. Depending on the application's functionality, this could lead to unintended data disclosure (e.g., submitting forms, changing settings) with low confidentiality and integrity impact, as per CVSS vector (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). The attacker does not gain direct access but can trick the victim into performing actions on their behalf [1].

Mitigation

The vulnerability is fixed in IBM Security Information Queue version 1.0.3 and later. IBM recommends upgrading to the latest version from the Docker Hub repository ibmcorp/security_information_queue. There is no workaround listed for versions 1.0.0–1.0.2 other than upgrading. No known KEV listing exists [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.