QID 376106
Date Published: 2021-11-30
QID 376106: IBM MQ Denial of Service (DoS) Vulnerability (6516422)
IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.
Eclipse Jetty is vulnerable to a denial of service, caused by improper input validation.
Affected Version:
IBM MQ 9.0.0, 9.1.0, 9.2.0
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
By sending a specially-crafted TLS frame, a remote attacker could exploit this vulnerability to cause CPU resources to reach to 100% usage.
- 6516422 -
www.ibm.com/support/pages/node/6516422
CVEs related to QID 376106
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6516422 |
|