QID 378560
Date Published: 2023-06-29
QID 378560: IBM MQ LibcURL Multiple Vulnerabilities (6952185)
IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.
IBM MQ could allow an authenticated and authorized user to cause a denial of service to the MQTT channels.
Affected Version:
IBM MQ 9.0,9.1,9.2,9.3 LTS
IBM MQ 9.1,9.2,9.3 CD
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Note: This QID does not checks for IBM MQ installable components, hence kept as practice
Successful exploitation of this vulnerability an attacker could exploit this vulnerability to reuse a previously created FTP connection.
- 6986579 -
www.ibm.com/support/pages/node/6986579
CVEs related to QID 378560
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6986579 |
|