QID 375523
Date Published: 2021-05-17
QID 375523: IBM MQ Remote Code Execution Vulnerability(6408626)
The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use.
An issue was found within the IBM MQ Java and JMS client libraries that could allow an attacker to execute a remote code execution attack.
Affected Versions:
IBM MQ 9.2.0
IBM MQ 9.1.0
IBM MQ 9.0.0
IBM MQ 8.0.0
IBM MQ 7.5.0
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Operating System: Linux
The QID executes /opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.
Successful exploitation of this vulnerability could allow an attacker to execute a remote code execution attack.
Solution
The vendor has released a fix to resolve the issue, please refer to 6408626 for more information.
Vendor References
- 6408626 -
www.ibm.com/support/pages/node/6408626
CVEs related to QID 375523
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6408626 |
|