QID 379385
QID 379385: IBM MQ AMQP Listeners Vulnerability (886899)
AIBM MQ AMQP Listeners are vulnerable to a session fixation attack (CVE-2019-4227)
Affected Version:
IBM MQ 8.0,9.0,9.1.9.1CD
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
A remote attacker could exploit this vulnerability to cause a denial of service condition.
Solution
Please refer to advisory IBM MQ 886899 for further information.
Vendor References
CVEs related to QID 379385
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 886899 |
|