Lucene search

K
ibmIBM12A8B770E0BBB7B775E52F5F749809C651AC285BCE9E4001004DDFEBE4CB6588
HistorySep 16, 2019 - 10:08 a.m.

Security Bulletin: IBM MQ is vulnerable to a denial of service attack within the error logging function (CVE-2019-4049)

2019-09-1610:08:18
www.ibm.com
7

EPSS

0

Percentile

5.1%

Summary

An error was found in the error logging functionality which could allow an attacker to consume disk space on the underlying filesystem. This could cause a denial of service attack.

Vulnerability Details

CVEID: CVE-2019-4049 DESCRIPTION: IBM WebSphere MQ is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service.
CVSS Base Score: 6.2
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/156398&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

IBM MQ V9.1 LTS

versions 9.1.0.0 - 9.1.0.2

IBM MQ V9.1 CD

version 9.1.1

Remediation/Fixes

IBM MQ V9.1 LTS

Apply FixPack 9.1.0.3

IBM MQ V9.1 CD

Upgrade to version 9.1.2

Workarounds and Mitigations

None.

EPSS

0

Percentile

5.1%

Related for 12A8B770E0BBB7B775E52F5F749809C651AC285BCE9E4001004DDFEBE4CB6588