QID 730845

Date Published: 2023-07-24

QID 730845: IBM MQ Appliance Denial-of Service Vulnerability (7007743)

Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by not limiting the number of request parts to be processed in the file upload function. By sending a specially-crafted request with series of uploads, a remote attacker could exploit this vulnerability to cause a denial of service condition.

IBM MQ is vulnerable to denial of service (DoS) attack.

Affected Versions:
IBM MQ Appliance 9.2 LTS prior to 9.2.0.15
IBM MQ Appliance 9.2 CD prior to 9.2.5.8
IBM MQ Appliance 9.3 LTS prior to 9.3.0.6
IBM MQ Appliance 9.3 CD prior to 9.3.3

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful exploitation of these vulnerabilities may allow an attacker to cause denial of service attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    Vendor has released the patch, please refer to advisory 7007743.
    Vendor References

    CVEs related to QID 730845

    Software Advisories
    Advisory ID Software Component Link
    7007743 URL Logo www.ibm.com/support/pages/node/7007743