IBM MQ Appliance Vulnerable to Heap-Based Buffer Overflow
CVE-2024-25048

7.5HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
27 April 2024

Summary

The IBM MQ Appliance version 9.3 CD and LTS is susceptible to a heap-based buffer overflow due to inadequate bounds checking mechanisms. This vulnerability can be exploited by a remote authenticated attacker, allowing them to overflow a buffer, which could lead to the execution of arbitrary code on the affected system or may result in the server crashing. Mitigating this risk is crucial to maintaining system integrity and security.

Affected Version(s)

MQ Appliance 9.3 LTS, 9.3 CD

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.