Lucene search

K
ibmIBMA2C8E2CF672AC451E5F568D88ED15C956CC420B68B1A498D23EF4F2087430CE6
HistoryMay 19, 2021 - 11:57 a.m.

Security Bulletin: IBM MQ is affected by a vulnerability within libcurl (CVE-2020-8284)

2021-05-1911:57:46
www.ibm.com
26
ibm mq
libcurl
vulnerability
remote attacker
sensitive information
ftp
apar it35440
fixpack 9.2.0.2
upgrade

EPSS

0.001

Percentile

45.3%

Summary

An issue was found within cURL libcurl that IBM MQ uses. This issue could affect users of the CCDTURL feature.

Vulnerability Details

CVEID:CVE-2020-8284
**DESCRIPTION:**cURL libcurl could allow a remote attacker to obtain sensitive information, caused by improper validation of FTP PASV responses. By persuading a victim to connect a specially-crafted server, an attacker could exploit this vulnerability to obtain sensitive information about services, and use this information to launch further attacks against the affected system.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/192854 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.2 CD
IBM MQ 9.2 LTS
IBM MQ 9.1 LTS
IBM MQ 9.0 LTS

Remediation/Fixes

This issue was resolved via APAR IT35440

IBM MQ 9.0 LTS

Apply iFix for APAR IT35440

IBM MQ 9.1 LTS

Apply iFix for APAR IT35440

IBM MQ 9.2 LTS

Apply FixPack 9.2.0.2

IBM MQ 9.2 CD

Upgrade to IBM MQ 9.2.2

Workarounds and Mitigations

None