QID 730076

Date Published: 2021-05-12

QID 730076: IBM MQ Appliance Denial of Service Vulnerability (6403285)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

CVE-2018-20843: libexpat is vulnerable to a denial of service, caused by an error in the XML parser. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to consume all available CPU resources.

CVE-2019-15903: libexpat is vulnerable to a denial of service, caused by a heap-based buffer over-read in XML_GetCurrentLineNumber. By using a specially-crafted XML input, a remote attacker could exploit this vulnerability to cause the application to crash.

Affected Versions:
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.1 CD
IBM MQ Appliance 9.2 LTS
IBM MQ Appliance 9.2 CD
QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

By using a specially-crafted XML input, a remote attacker could exploit this vulnerability to cause the application to crash.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Please refer to advisory 6403285
    Vendor References

    CVEs related to QID 730076

    Software Advisories
    Advisory ID Software Component Link
    6403285 URL Logo www.ibm.com/support/pages/node/6403285