Lucene search

K
ibmIBM1327D03B53BB97B3706B90393FED6D63E68660DACBF6A8C311EAC87127B93461
HistoryNov 15, 2021 - 3:40 p.m.

Security Bulletin: IBM MQ Java/JMS clients can inadvertently display cleartext credentials via diagnostic logs (CVE-2021-38949)

2021-11-1515:40:22
www.ibm.com
20
ibm mq
java clients
jms clients
clear text credentials
diagnostics logs
cve-2021-38949
apar it29154
fixpack 8.0.0.14
fixpack 9.0.0.9
fixpack 9.1.0.5
upgrade to ibm mq 9.1.5 cd

EPSS

0

Percentile

5.1%

Summary

An issue was idenitifed in IBM MQ Java and JMS clients where they could display clear text credentials in diagnostics log files automatically generated during system crashes.

Vulnerability Details

CVEID:CVE-2021-38949
**DESCRIPTION:**IBM MQ stores user credentials in plain clear text which can be read by a local user.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211403 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.1 LTS
IBM MQ 9.1 CD
IBM MQ 9.0 LTS
IBM MQ 8.0
IBM WebSphere MQ 7.5

Remediation/Fixes

This issue was resolved in APAR IT29154

WebSphere MQ version 7.5

Contact IBM Support and request a fix for APAR IT29154

IBM MQ version 8

Apply FixPack 8.0.0.14

IBM MQ version 9.0 LTS

Apply FixPack 9.0.0.9

IBM MQ version 9.1 LTS

Apply FixPack 9.1.0.5

IBM MQ version 9.1 CD

Upgrade to IBM MQ 9.1.5 CD

Workarounds and Mitigations

None

EPSS

0

Percentile

5.1%

Related for 1327D03B53BB97B3706B90393FED6D63E68660DACBF6A8C311EAC87127B93461