First published: Thu Jun 06 2019(Updated: )
IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 159226.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Information Queue | =1.0.0 | |
IBM Security Information Queue | =1.0.1 | |
IBM Security Information Queue | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4217 is considered a high severity vulnerability due to the potential for remote click hijacking.
To fix CVE-2019-4217, upgrade IBM Security Information Queue to version 1.0.3 or later.
CVE-2019-4217 can be exploited through social engineering tactics that lead victims to malicious websites.
CVE-2019-4217 affects IBM Security Information Queue versions 1.0.0, 1.0.1, and 1.0.2.
Users of IBM Security Information Queue who access malicious websites are at risk from CVE-2019-4217.