CVE-2022-40230
Summary
| CVE | CVE-2022-40230 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-03 20:15:00 UTC |
| Updated | 2022-11-04 17:14:00 UTC |
| Description | "IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532." |
Risk And Classification
Problem Types: CWE-613
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Mq Appliance | 9.2.0.0 | All | All | All |
| Application | Ibm | Mq Appliance | 9.2.0.0 | All | All | All |
| Application | Ibm | Mq Appliance | 9.3.0.0 | All | All | All |
| Application | Ibm | Mq Appliance | 9.3.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: IBM MQ Appliance is vulnerable to improper session invalidation (CVE-2022-40230) | MISC | www.ibm.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.