Lucene search

K
ibmIBM232C94A888E8FF258ED7DDB06364BC7C30EB6ED7B8458A1276976A97EFFF32FE
HistoryJul 23, 2020 - 9:29 p.m.

Security Bulletin: IBM MQ Appliance is affected by a denial of service vulnerability (CVE-2018-18066)

2020-07-2321:29:05
www.ibm.com
17
ibm mq appliance
denial of service
vulnerability
cve-2018-18066
net-snmp
fixpack 9.1.0.6
high availability

EPSS

0.004

Percentile

73.3%

Summary

IBM MQ Appliance has resolved a denial of service vulnerability.

Vulnerability Details

CVEID:CVE-2018-18066
**DESCRIPTION:**Net-SNMP is vulnerable to a denial of service, caused by an error in snmp_oid_compare in snmplib/snmp_api.c. By sending a specially-crafted UDP packet, a remote attacker could exploit this vulnerability to cause the instance to crash.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/150992 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.1 CD

Remediation/Fixes

IBM MQ Appliance 9.1 LTS

Apply fixpack 9.1.0.6, or later.

IBM MQ Appliance 9.1 CD

Apply IBM MQ Appliance 9.2, or later.

Workarounds and Mitigations

Only affects IBM MQ Appliance when configured in a High Availability group.

EPSS

0.004

Percentile

73.3%