CVE-2020-4290
Description
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM ISIQ 1.0.0–1.0.5 lets any authenticated user spoof another user's configuration owner, leading to info disclosure or unauthorized access.
Vulnerability
IBM Security Information Queue (ISIQ) versions 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 contain a security flaw where the product's configuration owner is determined by a client-supplied request object. An authenticated user can modify the owner field in that object to claim ownership of any other configured product, thereby bypassing the intended access controls [1].
Exploitation
An attacker must be authenticated to the ISIQ instance. By intercepting or crafting a product configuration request, the attacker changes the owner value to a target user's identity. No special network position or user interaction is required beyond standard authenticated API access [1].
Impact
Successful exploitation allows the attacker to assume the configuration owner role of another user, which can lead to disclosure of sensitive configuration data and unauthorized access to managed products. The CIA outcome is limited to low confidentiality and low integrity impacts (CVSS 4.2) [1].
Mitigation
IBM fixed the issue in ISIQ version 1.0.6 by no longer deriving the owner from the configuration request object. Users should upgrade to 1.0.6 or later. No workarounds are available for earlier versions [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5
- Range: 1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- exchange.xforce.ibmcloud.com/vulnerabilities/176333mitrevdb-entryx_refsource_XF
- www.ibm.com/support/pages/node/6172599mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.