QID 731086

Date Published: 2024-01-24

QID 731086: IBM MQ Appliance Denial-of Service Vulnerability (7060770)

IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.

CVE-2023-45177: IBM MQ is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic.

Affected Versions:
IBM MQ Appliance 9.2 LTS prior to 9.2.0.20
IBM MQ Appliance 9.3 LTS prior to 9.3.0.10
IBM MQ Appliance 9.3 CD prior to 9.3.4

QID Detection Logic(unauthenticated):
This QID checks for the vulnerable version of IBM MQ

Successful exploitation of these vulnerabilities may allow an attacker to cause denial of service attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Vendor has released the patch, please refer to advisory 7060770.
    Vendor References

    CVEs related to QID 731086

    Software Advisories
    Advisory ID Software Component Link
    7060770 URL Logo www.ibm.com/support/pages/node/7060770