Lucene search

K
ibmIBM8536D8B63174615B39C6AF8F68F74A50B7964CDD4E6D798DA69521E1FA81F86C
HistoryJul 31, 2018 - 1:44 p.m.

Security Bulletin: IBM MQ Appliance affected by an OpenSSL vulnerability (CVE-2018-0739)

2018-07-3113:44:49
www.ibm.com
9

0.009 Low

EPSS

Percentile

83.0%

Summary

IBM MQ Appliance has addressed the following vulnerability. OpenSSL is vulnerable to a denial of service.

Vulnerability Details

CVEID: CVE-2018-0739 DESCRIPTION: OpenSSL is vulnerable to a denial of service. By sending specially crafted ASN.1 data with a recursive definition, a remote attacker could exploit this vulnerability to consume excessive stack memory.
CVSS Base Score: 5.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/140847&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM MQ Appliance 8.0

Maintenance levels between 8.0.0.0 and 8.0.0.9

IBM MQ Appliance 9.0.x Continuous Delivery (CD) Release

Maintenance levels between 9.0.1 and 9.0.5

Remediation/Fixes

IBM MQ Appliance 8.0

Apply fixpack 8.0.0.10 or later

IBM MQ Appliance 9.0.x Continuous Delivery (CD) Release

Apply 9.1 Long Term Support (LTS) release

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm mq applianceeqany