Information Disclosure in IBM MQ and IBM MQ Appliance
CVE-2020-4319

3.1LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
28 July 2020

Summary

IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop versions 8.0 and 9.1 LTS/CD may expose sensitive information under specific conditions. An authenticated user could exploit a data leak caused by error messages in the pre-v7 pubsub logic, leading to unauthorized data access. For further details, you can refer to IBM's official support page and their vulnerability database.

Affected Version(s)

MQ Appliance 8.0

MQ Appliance 9.1.LTS

MQ Appliance 9.1.CD

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.