A vulnerability was discovered within the TLS key renegotiation functions which could be exploited to execute a denial of service attack against an IBM MQ queue manager.
CVEID: CVE-2019-4055 DESCRIPTION: IBM MQ is vulnerable to a denial of service attack within the TLS key renegotiation function.
CVSS Base Score: 7.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156564> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
IBM MQ and IBM MQ Appliance V8
versions 8.0.0.0 - 8.0.0.10
IBM MQ V9 LTS
versions 9.0.0.0 - 9.0.0.5
IBM MQ_and IBM MQ Appliance _V9.1 LTS
versions 9.1.0.0 - 9.1.0.1
IBM MQ_and IBM MQ Appliance _V9.1 CD
versions 9.1.0 - 9.1.1
IBM MQ and IBM MQ Appliance V8
IBM MQ V9 LTS
IBM MQ_and IBM MQ Appliance _V9.1 LTS
IBM MQ_and IBM MQ Appliance _V9.1 CD
None