QID 375395
Date Published: 2021-03-23
QID 375395: IBM MQ DOS Vulnerability(303559)
The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use. The main use of IBM MQ is to send or exchange messages. One application puts a message on a queue on one computer, and another application gets the same message from another queue on a different computer.
CVE-2018-1371: An IBM MQ client connecting to an MQ queue manager can cause a SIGSEGV in the amqrmppa channel process terminating it.
Affected Versions:
IBM MQ V 8.0.0.8
IBM MQ V9 LTS 9.0.0.2
IBM MQ version 9.0.4
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Successful exploitation of this vulnerability could leads to cause Denial of service and may crash the process.
CVEs related to QID 375395
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 303559 |
|