Lucene search

K
ibmIBMD476938EFEC3799A07C502302445D84E5A46466F1013CD42868F86CE1E60924E
HistoryJan 27, 2021 - 3:34 p.m.

Security Bulletin: The version of WebSphere Liberty shipped with IBM MQ is vulnerable to CVE-2020-4590

2021-01-2715:34:46
www.ibm.com
12
ibm mq
websphere liberty
cve-2020-4590
denial of service
apar it34473
fixpack
upgrade

EPSS

0.001

Percentile

32.8%

Summary

IBM MQ ships a version of WebSphere Liberty to provide the Web Console functionality. This version of liberty is vulnerable to CVE-2020-4590.

Vulnerability Details

CVEID:CVE-2020-4590
**DESCRIPTION:**IBM WebSphere Application Server Liberty 17.0.0.3 through 20.0.0.9 running oauth-2.0 or openidConnectServer-1.0 server features is vulnerable to a denial of service attack conducted by an authenticated client. IBM X-Force ID: 184650.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/184650 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.1 LTS
IBM MQ 9.2 CD
IBM MQ 9.2 LTS

Remediation/Fixes

This issue is addressed in MQ releases by APAR IT34473

IBM MQ versions 9.1 LTS

Apply Fixpack 9.1.0.7

IBM MQ version 9.2 LTS

Apply the WebSphere Liberty iFix listed on CVE-2020-4590

IBM MQ version 9.2 CD

Upgrade to IBM MQ 9.2.1

Workarounds and Mitigations

None

EPSS

0.001

Percentile

32.8%

Related for D476938EFEC3799A07C502302445D84E5A46466F1013CD42868F86CE1E60924E