QID 730819
Date Published: 2023-06-21
QID 730819: IBM MQ Appliance Improper Session Management Vulnerability (6560032)
IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.
IBM MQ Appliance does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Versions:
IBM MQ Appliance version 9.2 LTS prior to 9.2.0.4
IBM MQ Appliance version 9.2 CD prior to 9.2.5
QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ
Successful exploitation of this vulnerability may allow an authenticated user to impersonate another user on the system.
Solution
Vendor has released the patch, please refer to advisory 6560032.
Vendor References
- 6560032 -
www.ibm.com/support/pages/node/6560032
CVEs related to QID 730819
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6560032 |
|