QID 375650

Date Published: 2021-08-23

QID 375650: IBM MQ Buffer Overflow Vulnerability (6453367)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

Eclipse OpenJ9 is vulnerable to a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.

Affected Versions:

IBM MQ 9.2 LTS
IBM MQ 9.1 LTS
IBM MQ 9.0 LTS
IBM MQ 9.2 CD
IBM MQ 9.1 CD
IBM MQ 8.0
Operating System: Linux
The QID executes /opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.

Successful exploitation could cause the application to crash

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has released a fix to resolve the issue, please refer to 6453367 for more information.

    Vendor References

    CVEs related to QID 375650

    Software Advisories
    Advisory ID Software Component Link
    6453367 URL Logo www.ibm.com/support/pages/node/6453367