QID 378100

Date Published: 2023-05-02

QID 378100: IBM MQ Blockchain Bridge Vulnerability (6952185)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ could allow an authenticated and authorized user to cause a denial of service to the MQTT channels.
Affected Version:
IBM MQ 9.2, 9.3

QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.

Note: This QID does not checks for IBM MQ installable components, hence kept as practice

Successful exploitation could result IBM MQ Blockchain bridge package to provide Blockchain functionality in IBM MQ..

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution
    Please refer to advisory IBM MQ 6952185 for further information.

    Vendor References

    CVEs related to QID 378100

    Software Advisories
    Advisory ID Software Component Link
    6952185 URL Logo www.ibm.com/support/pages/node/6952185