Lucene search

K
ibmIBMF6A1B3086B45B3DCD0D5832F589E18092A1D03E94ACD32C8D56FFB1459A32692
HistoryJun 15, 2018 - 7:07 a.m.

Security Bulletin: Incorrect saved channel status enquiry could cause denial of service for IBM MQ (CVE-2017-1236)

2018-06-1507:07:34
www.ibm.com
6

0.001 Low

EPSS

Percentile

44.3%

Summary

IBM MQ could allow an authenticated user to potentially cause a denial of service by issuing an incorrect saved channel status inquiry.

Vulnerability Details

CVEID: CVE-2017-1236**
DESCRIPTION:** IBM MQ could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry.
CVSS Base Score: 3.1
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/124354&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

IBM MQ 9.0.2 Continuous Delivery

IBM MQ Appliance 9.0.x Continuous Delivery

IBM MQ 9.0 LTS

IBM MQ 8.0

IBM MQ 8.0 Appliance

Remediation/Fixes

IBM MQ 9.0.2 Continuous Delivery

Apply IBM MQ 9.0.3 Continuous Delivery release or later.

IBM MQ Appliance 9.0.x Continuous Delivery

Apply continuous delivery update 9.0.3 or later.

IBM MQ 9.0 LTS

Apply Fix Pack 9.0.0.2.

IBM MQ 8.0

Apply Fix Pack 8.0.0.7.

IBM MQ Appliance 8.0

Apply Fix Pack 8.0.0.7.

Workarounds and Mitigations

IBM MQ Appliance; Affected Queue manager must be restarted.

IBM MQ 9.0.2 CD : Restart the failed command server on the queue manager.

IBM MQ 9.0 LTS : Restart the failed command server on the queue manager.

IBM MQ 8.0 : Restart the failed command server on the queue manager.

0.001 Low

EPSS

Percentile

44.3%

Related for F6A1B3086B45B3DCD0D5832F589E18092A1D03E94ACD32C8D56FFB1459A32692