IBM Security Information Queue (ISIQ) reveals too much internal data when displaying application error messages. This data could be used by an attacker. As of v1.0.3, ISIQβs displayed errors are more terse. Detailed diagnostic data is only written to ISIQ log files.
CVEID: CVE-2019-4219 DESCRIPTION: IBM Security Information Queue (ISIQ) generates an error message that includes sensitive information that could be used in further attacks against the system.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/159228> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
IBM Security Information Queue v1.0.0, v1.0.1, and v1.0.2
Download and install the latest IBM Security Information Queue images (tagged at 1.0.3 or greater) from the Docker Hub repository, βibmcorp/security_information_queueβ:
<https://cloud.docker.com/u/ibmcorp/repository/docker/ibmcorp/security_information_queue>