Lucene search

K
ibmIBMFE1F6F711B6154D739FA1A126FF06B3E7AA98A63CF40D7650900F6C1526E2AAD
HistorySep 05, 2024 - 9:37 p.m.

Security Bulletin: IBM MQ is vulnerable to a denial of service (CVE-2024-40680)

2024-09-0521:37:52
www.ibm.com
11
ibm mq
denial of service
vulnerability
versions 9.3 cd
9.4 lts
9.4 cd
fix pack

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.5%

Summary

IBM MQ has addressed a denial of service vulnerability.

Vulnerability Details

CVEID:CVE-2024-40680
**DESCRIPTION:**IBM MQ could allow a local user to cause a denial of service due to improper memory allocation causing a segmentation fault.
CVSS Base score: 6.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/297611 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM MQ 9.3 CD
IBM MQ 9.4 LTS and CD

The following installable MQ components are affected by the vulnerability:

- Server

If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see <https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins&gt;

Remediation/Fixes

This issue was addressed under APAR IT45634.

IBM MQ version 9.3 CD

Upgrade to IBM MQ version 9.4 and apply fix pack 9.4.0.5

IBM MQ version 9.4 LTS and CD

Apply fix pack 9.4.0.5

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmmqMatch9.3
OR
ibmmqMatch9.4
VendorProductVersionCPE
ibmmq9.3cpe:2.3:a:ibm:mq:9.3:*:*:*:*:*:*:*
ibmmq9.4cpe:2.3:a:ibm:mq:9.4:*:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.5%

Related for FE1F6F711B6154D739FA1A126FF06B3E7AA98A63CF40D7650900F6C1526E2AAD