{"api_version":"1","generated_at":"2026-07-23T13:43:44+00:00","cve":"CVE-2023-26284","urls":{"html":"https://cve.report/CVE-2023-26284","api":"https://cve.report/api/cve/CVE-2023-26284.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-26284","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-26284"},"summary":{"title":"CVE-2023-26284","description":"IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2023-03-15 18:15:00","updated_at":"2023-11-07 04:09:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/248417","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/248417","refsource":"MISC","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.ibm.com/support/pages/node/6960201","name":"https://www.ibm.com/support/pages/node/6960201","refsource":"MISC","tags":[],"title":"Security Bulletin: Insufficient authorization check in IBM supplied MQ Advanced for Integration container image (CVE-2023-26284)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-26284","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26284","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"26284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"mq_certified_container","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"continous_delivery","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"26284","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"mq_certified_container","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-26284","ASSIGNER":"psirt@us.ibm.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"284 Improper Access Control"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"MQ Certified Container","version":{"version_data":[{"version_affected":"<","version_name":"9.3.0.1","version_value":"9.3.0.3"},{"version_affected":"<","version_name":"9.3.1.0","version_value":"9.3.1.1"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.ibm.com/support/pages/node/6960201","refsource":"MISC","name":"https://www.ibm.com/support/pages/node/6960201"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/248417","refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/248417"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-03-15 18:15:00","lastModifiedDate":"2023-11-07 04:09:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:continous_delivery:*:*:*","versionStartIncluding":"9.3.1.0","versionEndExcluding":"9.3.2.0","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:lts:*:*:*","versionStartIncluding":"9.3.0.1","versionEndExcluding":"9.3.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}