Lucene search

K
ibmIBM8BD61AD606D37FA758336C2F5925686FA94C574196B207AB5552AA30A3B973FC
HistoryJan 20, 2021 - 12:27 p.m.

Security Bulletin: IBM MQ Appliance is affected by a libssh2 vulnerability (CVE-2019-17498)

2021-01-2012:27:52
www.ibm.com
12

0.004 Low

EPSS

Percentile

73.9%

Summary

IBM MQ Appliance has resolved a libssh2 vulnerability.

Vulnerability Details

CVEID:CVE-2019-17498
**DESCRIPTION:**libssh2 is vulnerable to a denial of service, caused by an out-of-bounds read when connecting to a malicious SSH server that sends a disconnect message. A remote attacker could exploit this vulnerability to cause a denial of service or obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/169461 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.2 LTS
IBM MQ Appliance 9.1 CD

Remediation/Fixes

IBM MQ Appliance 9.1 LTS

Apply fixpack 9.1.0.7, or later maintenance.

IBM MQ Appliance 9.1 CD

Upgrade to 9.2.1 CD, or later.

IBM MQ Appliance 9.2 LTS

Apply iFix IT34570, or later maintenance.

Workarounds and Mitigations

None