Lucene search

K
ibmIBM48743691B199137A582CC22605BCF99658033695C6D69E50041B31A074707355
HistoryJul 23, 2020 - 9:32 p.m.

Security Bulletin: IBM MQ Appliance affected by an OpenSSL vulnerability (CVE-2019-1551)

2020-07-2321:32:18
www.ibm.com
6

0.002 Low

EPSS

Percentile

60.1%

Summary

IBM MQ Appliance has addressed the following OpenSSL vulnerability.

Vulnerability Details

CVEID:CVE-2019-1551
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by an overflow in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. By performing a man-in-the-middle attack, a remote attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/172752 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 8.0
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.1 CD

Remediation/Fixes

IBM MQ Appliance 8.0

Apply fixpack 8.0.0.15, or later.

IBM MQ Appliance 9.1 LTS

Apply fixpack 9.1.0.6, or later.

IBM MQ Appliance 9.1 CD

Apply IBM MQ Appliance 9.2, or later.

Workarounds and Mitigations

None