Lucene search

K
nvd[email protected]NVD:CVE-2024-39742
HistoryJul 08, 2024 - 2:15 p.m.

CVE-2024-39742

2024-07-0814:15:02
CWE-187
CWE-697
web.nvd.nist.gov
11
ibm mq operator
authentication bypass
vulnerability
string comparison

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

32.4%

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.

Affected configurations

Nvd
Node
ibmmq_operatorRange2.0.02.0.24
OR
ibmmq_operatorRange2.2.02.2.2
OR
ibmmq_operatorRange2.3.02.3.3
OR
ibmmq_operatorRange2.4.02.4.8
OR
ibmmq_operatorRange3.1.03.1.3
OR
ibmmq_operatorRange3.2.03.2.2
OR
ibmmq_operatorMatch3.0.0
OR
ibmmq_operatorMatch3.0.1
VendorProductVersionCPE
ibmmq_operator*cpe:2.3:a:ibm:mq_operator:*:*:*:*:*:*:*:*
ibmmq_operator3.0.0cpe:2.3:a:ibm:mq_operator:3.0.0:*:*:*:*:*:*:*
ibmmq_operator3.0.1cpe:2.3:a:ibm:mq_operator:3.0.1:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

32.4%

Related for NVD:CVE-2024-39742