QID 375396
Date Published: 2021-03-24
QID 375396: IBM MQ information Disclosure Vulnerability(714925)
The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use. The main use of IBM MQ is to send or exchange messages. One application puts a message on a queue on one computer, and another application gets the same message from another queue on a different computer.
CVE-2017-1337: IBM MQ Java/JMS application can incorrectly transmit user credentials in plain text.
Affected Versions:
IBM MQ 8.0.0.0 - 8.0.0.6
IBM MQ 9.0.0.0 - 9.0.0.1
IBM MQ V9.0.1 and V9.0.2
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Operating System: Linux
The QID executes /opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.
Successful exploitation of this vulnerability could transmit user credentials in plain text which leads to information disclosure to the attacker.
CVEs related to QID 375396
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 714925 |
|