Lucene search

K
ibmIBM35D1E45A6FF037C1540CB831E6C3246FD914D1D2E5779992569AB888C7FF905D
HistoryJul 23, 2020 - 9:33 p.m.

Security Bulletin: IBM MQ Appliance is affected by an information disclosure vulnerability (CVE-2020-4498)

2020-07-2321:33:28
www.ibm.com
11

EPSS

0

Percentile

5.1%

Summary

IBM MQ Appliance has resovled an information disclosure vulnerability.

Vulnerability Details

CVEID:CVE-2020-4498
**DESCRIPTION:**IBM MQ could allow a local privileged user to obtain highly sensitve information due to inclusion of data within trace files.
CVSS Base score: 4.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/182118 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.1 CD

Remediation/Fixes

IBM MQ Appliance 9.1 LTS

Apply fixpack 9.1.0.6, or later.

IBM MQ Appliance 9.1 CD

Apply IBM MQ Appliance 9.2, or later.

Workarounds and Mitigations

None

EPSS

0

Percentile

5.1%

Related for 35D1E45A6FF037C1540CB831E6C3246FD914D1D2E5779992569AB888C7FF905D