QID 730819

Date Published: 2023-06-21

QID 730819: IBM MQ Appliance Improper Session Management Vulnerability (6560032)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ Appliance does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Affected Versions:
IBM MQ Appliance version 9.2 LTS prior to 9.2.0.4
IBM MQ Appliance version 9.2 CD prior to 9.2.5

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful exploitation of this vulnerability may allow an authenticated user to impersonate another user on the system.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Vendor has released the patch, please refer to advisory 6560032.
    Vendor References

    CVEs related to QID 730819

    Software Advisories
    Advisory ID Software Component Link
    6560032 URL Logo www.ibm.com/support/pages/node/6560032