QID 730140

QID 730140: IBM MQ Appliance OpenSSL Vulnerability (6463293)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ OpenSSL is vulnerable to a denial of service, caused by a NULL pointer dereference in signature algorithms processing.

Affected Versions:
IBM MQ Appliance 9.2 LTS
IBM MQ Appliance 9.2 CD
QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful could allow an authenticated user to cause a denial of service due to an issue processing messages.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Please refer to advisory IBM MQ Appliance CVE-2021-3449
    Vendor References

    CVEs related to QID 730140

    Software Advisories
    Advisory ID Software Component Link
    6463293 URL Logo www.ibm.com/support/pages/node/6463293