QID 375682
Date Published: 2021-07-07
QID 375682: IBM MQ Control List Bypass Vulnerability(6464787)
IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.
ClusterLabs Pacemaker could allow a local attacker to bypass security restrictions, caused by an access control list bypass flaw.
Affected Version:
IBM MQ Version 9.1.0, 9.2.0
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Attacker could exploit this vulnerability to perform certain tasks prevented by ACLs.
Solution
Please refer to advisory IBM MQ 6464787 for further information.
Vendor References
- 6464787 -
www.ibm.com/support/pages/node/6464787
CVEs related to QID 375682
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6464787 |
|