QID 379445
Date Published: 2024-03-14
QID 379445: IBM MQ Denial of Service (DoS) Vulnerability (7123139)
IBM MQ provides a universal messaging backbone with robust connectivity for flexible and reliable messaging for applications and the integration of existing IT assets using a service-oriented architecture (SOA).
CVE-2024-25016: IBM MQ and IBM MQ Appliance could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic.
Affected Version:
IBM MQ 9.0 to prior to 9.0.0.23
IBM MQ 9.1 to prior to 9.1.0.20
IBM MQ 9.2 to prior to 9.2.0.22
IBM MQ 9.3 to prior to 9.3.0.16
IBM MQ 9.3 to prior to 9.3.5 CD
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic.
- 7123139 -
www.ibm.com/support/pages/node/7123139
CVEs related to QID 379445
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 7123139 |
|