A vulnerability was identified in cURL that could allow a remote attacker to obtain sensitive information. cURL is included in the IBM MQ Advanced CloudPak for IBM Cloud Private on RedHat OpenShift.
CVEID: CVE-2018-16842 DESCRIPTION: cURL could allow a remote attacker to obtain sensitive information, caused by a heap-based buffer over-read in the display function in the command line tool. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information or cause a denial of service condition.
CVSS Base Score: 6.5
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/152300> for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)
IBM MQ Advanced Cloud Pak (IBM Cloud Private on RedHat OpenShift)
v2.1.0 - v 2.3.1
IBM MQ Advanced Cloud Pak (RedHat OpenShift)
Apply Fix IBM-MQ-Adv-Cloud-Pak-2.3.2-RHOS to upgrade to version v2.3.2
none