An issue was found within the IBM MQ Java and JMS client libraries that could allow an attacker to execute a remote code execution attack.
CVEID:CVE-2020-4682
**DESCRIPTION:**IBM MQ could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/186509 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM MQ | 9.2 CD |
IBM MQ | 9.2 LTS |
IBM MQ | 9.1 |
IBM MQ | 9.0 |
IBM MQ | 8.0 |
IBM WebSphere MQ | 7.5 |
This issue is addressed by APAR IT33772
IBM WebSphere MQ 7.5
Apply interim fix for APAR IT33772
IBM MQ 8.0
Apply interim fix for APAR IT33772
IBM MQ 9.0 LTS
IBM MQ 9.1 LTS
IBM MQ 9.2 LTS
IBM MQ 9.2 CD
None