Lucene search

K
ibmIBM08C9397BF11EF5271B24AC4C1FDC11821A52DAB7FBF85BE70C829ADF7D741BE3
HistoryApr 28, 2023 - 6:17 p.m.

Security Bulletin: IBM MQ Clients are vulnerable to a denial of service attack (CVE-2023-22874)

2023-04-2818:17:42
www.ibm.com
15
ibm mq
denial of service
vulnerability
configuration files
apar
fixpack

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

17.8%

Summary

An issue was identified that may cause IBM MQ Clients to be vulnerable to a denial of service attack when processing configuration files.

Vulnerability Details

CVEID:CVE-2023-22874
**DESCRIPTION:**IBM MQ Clients are vulnerable to a denial of service attack when processing configuration files.
CVSS Base score: 5.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/244216 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.2 CD
IBM MQ 9.3 CD
IBM MQ 9.3 LTS

The following installable MQ components are affected by the vulnerability:

- Standard Client

If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see <https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins&gt;

Remediation/Fixes

This issue was resolved under APAR IT42812

IBM MQ 9.3 LTS

Apply FixPack 9.3.0.5

IBM MQ 9.2 CD and 9.3 CD

Upgrade to IBM MQ 9.3.2

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmqMatch9.2.4
OR
ibmmqMatch9.2.5
OR
ibmmqMatch9.3.0
OR
ibmmqMatch9.3.1
OR
ibmmqMatch9.3.2
VendorProductVersionCPE
ibmmq9.2.4cpe:2.3:a:ibm:mq:9.2.4:*:*:*:*:*:*:*
ibmmq9.2.5cpe:2.3:a:ibm:mq:9.2.5:*:*:*:*:*:*:*
ibmmq9.3.0cpe:2.3:a:ibm:mq:9.3.0:*:*:*:*:*:*:*
ibmmq9.3.1cpe:2.3:a:ibm:mq:9.3.1:*:*:*:*:*:*:*
ibmmq9.3.2cpe:2.3:a:ibm:mq:9.3.2:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

17.8%

Related for 08C9397BF11EF5271B24AC4C1FDC11821A52DAB7FBF85BE70C829ADF7D741BE3