Denial of Service Vulnerability in IBM MQ by IBM
CVE-2021-29843

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
8 November 2021

Summary

IBM MQ versions 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2 CD are susceptible to a denial of service attack due to an issue that arises when processing message properties. This vulnerability may allow attackers to disrupt the normal operations of the messaging system, potentially leading to significant downtime and service interruptions for applications relying on IBM MQ for message delivery.

Affected Version(s)

MQ Appliance 9.1.LTS

MQ Appliance 9.1.CD

MQ Appliance 9.2.LTS

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.