QID 375577

Date Published: 2021-05-24

QID 375577: IBM MQ Information Exposure Vulnerability (6393332)

The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use.

An issue was identified with Eclipse Jetty that is bundled within IBM MQ Explorer

Affected Versions:

IBM MQ 9.2.0.0
IBM MQ 9.2.0
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Operating System: Linux
The QID executes /opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.

An attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.

  • CVSS V3 rated as Critical - 9.4 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released a fix to resolve the issue, please refer to 6393332 for more information.

    Vendor References

    CVEs related to QID 375577

    Software Advisories
    Advisory ID Software Component Link
    6393332 URL Logo www.ibm.com/support/pages/node/6393332