Lucene search

K
ibmIBM3E113519C08ADA1A733C48B02DF364667DDCEA70A673219A31D93C7D1162E3D9
HistoryAug 31, 2023 - 3:28 p.m.

Security Bulletin: IBM MQ is affected by OpenSSL vulnerability (CVE-2023-2650)

2023-08-3115:28:15
www.ibm.com
13
ibm mq
openssl
denial of service
vulnerability
hpe nonstop
fix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%

Summary

IBM MQ is vulnerable to an OpenSSL vulnerability CVE-2023-2650 when conducting OCSP certificate operations.

Vulnerability Details

CVEID:CVE-2023-2650
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by a flaw when using OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/256611 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ for HPE NonStop 8.1.0

Remediation/Fixes

IBM MQ V8.1 for HPE NonStop 8.1.0.16 IT44398 Upgrade to CSU 8.1.0.16

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmq_for_hpe_nonstopMatch8.1
OR
ibmmq_for_hpe_nonstopMatch8.1

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.9%