Lucene search

K
ibmIBM2DC096ED3B0D04D896E244B56A6D5007BA4B76607A90314A62520873549DE877
HistoryApr 04, 2022 - 11:38 a.m.

Security Bulletin: IBM MQ Appliance affected by account enumeration and denial of service vulnerabilities (CVE-2022-22356 and CVE-2022-22355)

2022-04-0411:38:55
www.ibm.com
24
ibm
mq appliance
account enumeration
denial of service
vulnerabilities
cve-2022-22356
cve-2022-22355
ibm datapower gateway
fix
it40182

EPSS

0.001

Percentile

33.5%

Summary

IBM MQ Appliance has resolved account enumeration and denial of service vulnerabilities.

Vulnerability Details

CVEID:CVE-2022-22356
**DESCRIPTION:**IBM DataPower Gateway could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/220487 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N)

CVEID:CVE-2022-22355
**DESCRIPTION:**IBM MQ Appliance and IBM DataPower Gateway are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/220486 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.2 CD
IBM MQ Appliance 9.2 LTS

Remediation/Fixes

These vulnerabilities are addressed under IT40182

IBM strongly recommends addressing the vulnerability now.

IBM MQ Appliance version 9.2 LTS

Apply interim fix firmware for APAR IT40182, or later firmware.

IBM MQ Appliance version 9.2 CD

Apply interim fix firmware for APAR IT40182 , or later firmware.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

33.5%

Related for 2DC096ED3B0D04D896E244B56A6D5007BA4B76607A90314A62520873549DE877