QID 730031

Date Published: 2021-04-08

QID 730031: IBM MQ Appliance Multiple Vulnerabilities(6403297)

The IBM MQ Appliance is a hardware product that provides IBM MQ ready installed and ready to use. The main use of IBM MQ is to send or exchange messages. One application puts a message on a queue on one computer, and another application gets the same message from another queue on a different computer.

CVE-2019-19956: libxml2 is vulnerable to a denial of service, caused by a memory leak in xmlParseBalancedChunkMemoryRecover in parser.c. By persuading a victim to open a specially crafted file.
CVE-2019-20388: GNOME libxml2 could allow a remote attacker to obtain sensitive information, caused by an xmlSchemaValidateStream memory leak in xmlSchemaPreRun in xmlschemas.c.
CVE-2020-7595: The Gnome Project Libxml2 is vulnerable to a denial of service, caused by an error in xmlStringLenDecodeEntities in parser.c.

Affected Versions:
IBM MQ Appliance 9.1.0.0 - 9.1.0.6 LTS
IBM MQ Appliance 9.2.0.0 LTS
IBM MQ Appliance 9.1.0- 9.2.1 CD

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ Appliance

Successful exploitation of this vulnerability could allow a local user to cause the application to enter into an infinite loop and expose some sensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a fix to resolve the issue, please refer to 6403297 for more information.

    Vendor References

    CVEs related to QID 730031

    Software Advisories
    Advisory ID Software Component Link
    6403297 URL Logo www.ibm.com/support/pages/node/6403297