QID 730820

Date Published: 2023-06-27

QID 730820: IBM MQ Appliance Denial-of Service Vulnerability (6852713)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

IBM MQ is vulnerable to denial of service (DoS) attack.

Affected Versions:
IBM MQ Appliance 9.2 LTS prior to 9.2.0.7
IBM MQ Appliance 9.2 CD prior to 9.2.5 CSU04
IBM MQ Appliance 9.3 LTS prior to 9.3.0.2
IBM MQ Appliance 9.3 CD prior to 9.3.1.1

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful exploitation of these vulnerabilities may allow an attacker to cause denial of service attack.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Vendor has released the patch, please refer to advisory 6852713.
    Vendor References

    CVEs related to QID 730820

    Software Advisories
    Advisory ID Software Component Link
    6852713 URL Logo www.ibm.com/support/pages/node/6852713