IBM MQ ships a version of WebSphere Liberty to provide the Web Console functionality. This version of liberty is vulnerable to CVE-2020-4590.
CVEID:CVE-2020-4590
**DESCRIPTION:**IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/184650 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM MQ | 9.1 LTS |
IBM MQ | 9.2 CD |
IBM MQ | 9.2 LTS |
This issue is addressed in MQ releases by APAR IT34473
IBM MQ versions 9.1 LTS
IBM MQ version 9.2 LTS
Apply the WebSphere Liberty iFix listed on CVE-2020-4590
IBM MQ version 9.2 CD
None