QID 730818

Date Published: 2023-06-27

QID 730818: IBM MQ Appliance Multiple Security Vulnerabilities (6986567)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ is vulnerable to disclosure of sensitive information vulnerability and denial of service (DoS) attack.

Affected Versions:
IBM MQ Appliance 9.2 LTS prior to 9.2.0.11
IBM MQ Appliance 9.2 CD prior to 9.2.5.7
IBM MQ Appliance 9.3 LTS prior to 9.3.0.5
IBM MQ Appliance 9.3 CD prior to 9.3.2.1

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful exploitation of these vulnerabilities may allow an attacker to cause denial of service attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released the patch, please refer to advisory 6986567.
    Vendor References

    CVEs related to QID 730818

    Software Advisories
    Advisory ID Software Component Link
    6986567 URL Logo www.ibm.com/support/pages/node/6986567