QID 378672
Date Published: 2023-07-26
QID 378672: IBM MQ Denial of Service (DoS) Vulnerabilities (7007425)
Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by not limit the number of request parts to be processed in the file upload function. By sending a specially-crafted request with series of uploads, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Affected Version:
IBM MQ 9.1,9.2, 9.3
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
A remote attacker could exploit this vulnerability to cause a denial of service condition.
- 7007425 -
www.ibm.com/support/pages/node/7007425
CVEs related to QID 378672
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7007425 |
|