Lucene search

K
ibmIBM8623CE2DB2FC37730D93C08BF4B1A8FD03CE011C1F36E0B1F1CF9AFCB3DBA361
HistorySep 05, 2024 - 9:34 p.m.

Security Bulletin: IBM MQ Advanced Message Security on IBM i platform is affected by an issue in OpenSSL (CVE-2024-2511)

2024-09-0521:34:51
www.ibm.com
12
ibm mq
advanced message security
ibm i platform
openssl
vulnerability
cve-2024-2511
security updates

AI Score

6.8

Confidence

High

Summary

An issue was identified with OpenSSL, which IBM MQ on the IBM i platform uses within the Advanced Message Security feature to provide cryptographic functionality. It is not used for transport layer security (TLS) functionality for IBM MQ channel connections, which is provided by the IBM i SystemTLS libraries.

Vulnerability Details

CVEID:CVE-2024-2511
**DESCRIPTION:**OpenSSL is vulnerable to a denial of service, caused by improper server configuration validation. By using a specially crafted server configuration, a remote attacker could exploit this vulnerability to cause unbounded memory growth, and results in a denial of service condition.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/287215 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.0 LTS
IBM MQ 9.1 LTS
IBM MQ 9.2 LTS
IBM MQ 9.3 LTS
IBM MQ 9.4 LTS

The following installable MQ components are affected by the vulnerability:

- Advanced Message Security (AMS)

If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see <https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins&gt;

Remediation/Fixes

This issue was addressed under APAR IT46080.

IBM MQ version 9.0 LTS

Apply cumulative security update 9.0.0.27

IBM MQ version 9.1 LTS

Apply cumulative security update 9.1.0.23

IBM MQ version 9.2 LTS

Apply cumulative security update 9.2.0.27

IBM MQ version 9.3 LTS

Apply cumulative security update 9.3.0.21

IBM MQ version 9.4 LTS

Apply fix pack 9.4.0.5

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmqMatch9.0
OR
ibmmqMatch9.1
OR
ibmmqMatch9.2
OR
ibmmqMatch9.3
OR
ibmmqMatch9.4
VendorProductVersionCPE
ibmmq9.0cpe:2.3:a:ibm:mq:9.0:*:*:*:*:*:*:*
ibmmq9.1cpe:2.3:a:ibm:mq:9.1:*:*:*:*:*:*:*
ibmmq9.2cpe:2.3:a:ibm:mq:9.2:*:*:*:*:*:*:*
ibmmq9.3cpe:2.3:a:ibm:mq:9.3:*:*:*:*:*:*:*
ibmmq9.4cpe:2.3:a:ibm:mq:9.4:*:*:*:*:*:*:*