Lucene search

K
ibmIBM9F54582F911AD1DBFE847E2C4F2DC15D011ECFDBC2BCEF59FF4239D75B060721
HistoryDec 15, 2021 - 11:39 a.m.

Security Bulletin: IBM MQ Appliance is vulnerable to a denial of service attack (CVE-2021-38875)

2021-12-1511:39:42
www.ibm.com
5
ibm mq appliance
denial of service
vulnerability
cve-2021-38875
fixpack
upgrade
firmware
apar it36179

EPSS

0.001

Percentile

32.8%

Summary

IBM MQ Appliance has resolved a denial of service vulnerability.

Vulnerability Details

CVEID:CVE-2021-38875
**DESCRIPTION:**IBM MQ is vulnerable to a denial of service attack caused by an error processing messages.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/208398 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ Appliance 9.1 LTS
IBM MQ Appliance 9.2 CD
IBM MQ Appliance 9.2 LTS
IBM MQ Appliance 9.1 CD

Remediation/Fixes

This vulnerability is addressed under APAR IT36179.

IBM MQ Appliance version 9.1 LTS

Apply fixpack 9.1.0.9, or later firmware.

IBM MQ Appliance version 9.1 CD

Upgrade to 9.2.4 CD, or later firmware.

IBM MQ Appliance version 9.2 LTS

Apply fixpack 9.2.0.4, or later firmware.

IBM MQ Appliance version 9.2 CD

Upgrade to 9.2.4 CD, or later firmware.

Workarounds and Mitigations

None

EPSS

0.001

Percentile

32.8%

Related for 9F54582F911AD1DBFE847E2C4F2DC15D011ECFDBC2BCEF59FF4239D75B060721