QID 375436
Date Published: 2021-05-20
QID 375436: IBM MQ and IBM MQ Appliance DOS Vulnerability(6208035)
The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use. The main use of IBM MQ is to send or exchange messages. One application puts a message on a queue on one computer, and another application gets the same message from another queue on a different computer.
CVE-2019-4614: IBM MQ client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message.
Affected Versions:
IBM MQ V8.0.0.0 - 8.0.0.13
IBM MQ V9.0.0.0 - V9.0.0.7
IBM MQ V9.1.0.0 - V9.1.0.3
IBM MQ V9.1.1 - V9.1.3
IBM MQ Appliance V8.0.0.0 - V8.0.0.13
IBM MQ Appliance V9.1.1 - V9.1.3
IBM MQ Appliance V9.1.0.0 - V9.1.0.3
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ
Successful exploitation of this vulnerability could allow a local user to crash the queue manager agent thread and expose some sensitive information.
- 1106523 -
www.ibm.com/support/pages/node/1106523
CVEs related to QID 375436
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 1106517 |
|
||
| 1106523 |
|