QID 378553

Date Published: 2023-06-26

QID 378553: IBM MQ Blockchain bridge Denial of Service (DoS) Vulnerability within protobuf-java core (6853381)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

protobuf-java core and lite are vulnerable to a denial of service, caused by a flaw in the parsing procedure for binary and text format data.
Affected Version:
IBM MQ 9.2, 9.3

QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.

By sending non-repeated embedded messages with repeated or unknown fields, a remote authenticated attacker could exploit this vulnerability to cause long garbage collection pauses.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.1 severity.
  • Solution
    Please refer to advisory IBM MQ 6853381 for further information.

    Vendor References

    CVEs related to QID 378553

    Software Advisories
    Advisory ID Software Component Link
    6853381 URL Logo www.ibm.com/support/pages/node/6853381