Information Disclosure in IBM MQ and IBM MQ Appliance
CVE-2020-4319
3.1LOW
Summary
IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop versions 8.0 and 9.1 LTS/CD may expose sensitive information under specific conditions. An authenticated user could exploit a data leak caused by error messages in the pre-v7 pubsub logic, leading to unauthorized data access. For further details, you can refer to IBM's official support page and their vulnerability database.
Affected Version(s)
MQ Appliance 8.0
MQ Appliance 9.1.LTS
MQ Appliance 9.1.CD
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved