VYPR
Unrated severityNVD Advisory· Published Apr 8, 2020· Updated Sep 16, 2024

CVE-2020-4290

CVE-2020-4290

Description

IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

IBM ISIQ 1.0.0–1.0.5 lets any authenticated user spoof another user's configuration owner, leading to info disclosure or unauthorized access.

Vulnerability

IBM Security Information Queue (ISIQ) versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 contain a security flaw where the product's configuration owner is determined by a client-supplied request object. An authenticated user can modify the owner field in that object to claim ownership of any other configured product, thereby bypassing the intended access controls [1].

Exploitation

An attacker must be authenticated to the ISIQ instance. By intercepting or crafting a product configuration request, the attacker changes the owner value to a target user's identity. No special network position or user interaction is required beyond standard authenticated API access [1].

Impact

Successful exploitation allows the attacker to assume the configuration owner role of another user, which can lead to disclosure of sensitive configuration data and unauthorized access to managed products. The CIA outcome is limited to low confidentiality and low integrity impacts (CVSS 4.2) [1].

Mitigation

IBM fixed the issue in ISIQ version 1.0.6 by no longer deriving the owner from the configuration request object. Users should upgrade to 1.0.6 or later. No workarounds are available for earlier versions [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.