Lucene search

K
ibmIBMAF4901D92F640A015D388E851A3E455C8DC66F2CAA3CA19E1932470F7CBAF115
HistoryApr 03, 2024 - 10:00 a.m.

Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS are vulnerable to a remote unauthenticated attack due to IBM MQ (CVE-2024-25016)

2024-04-0310:00:01
www.ibm.com
25
ibm
app connect enterprise
integration bus
z/os
vulnerability
remote attack
unauthenticated
ibm mq
cve-2024-25016
fix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Summary

Features requiring MQ connectivity in IBM App Connect Enterprise and IBM Integration Bus for z/OS are vulnerable to a remote unauthenticated attack due to IBM MQ. This bulletin identifies the steps to take to address the vulnerability.

Vulnerability Details

CVEID:CVE-2024-25016
**DESCRIPTION:**IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of service due to incorrect buffering logic. IBM X-Force ID: 281279.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/281279 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM App Connect Enterprise 12.0.1.0 - 12.0.11.3
IBM App Connect Enterprise 11.0.0.1 - 11.0.0.25
IBM Integration Bus for z/OS 10.1 - 10.1.0.3

Remediation/Fixes

**IBM strongly recommends addressing the vulnerability/vulnerabilities now by applying the appropriate fix to IBM App Connect Enterprise and IBM Integration Bus for z/OS **

Affected Product(s)

|

Version(s)

| APAR|

Remediation / Fixes

—|—|—|—
IBM App Connect Enterprise| 12.0.1.0 - 12.0.11.3|

IT45719

|

The APAR (IT45719) is available from

IBM App Connect Enterprise v12- Fix Pack Release 12.0.12.0

IBM App Connect Enterprise| 11.0.0.1 - 11.0.0.25|

IT45719

|

Interim fix for APAR (IT45719) is available to apply to 11.0.0.25 from

IBM Fix Central

IBM Integration Bus for z/OS| 10.1 - 10.1.0.3|

IT45719

|

Interim fix for APAR (IT45719) is available to apply to 10.1.0.3 from

IBM Fix Central

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmapp_connect_enterpriseRange12.0.1.0
OR
ibmapp_connect_enterpriseRange12.0.11.3
OR
ibmapp_connect_enterpriseRange11.0.0.1
OR
ibmapp_connect_enterpriseRange11.0.0.25
OR
ibmintegration_busRange10.1
OR
ibmintegration_busRange10.1.0.3
VendorProductVersionCPE
ibmapp_connect_enterprise*cpe:2.3:a:ibm:app_connect_enterprise:*:*:*:*:*:*:*:*
ibmintegration_bus*cpe:2.3:a:ibm:integration_bus:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for AF4901D92F640A015D388E851A3E455C8DC66F2CAA3CA19E1932470F7CBAF115