Bypass Security Restrictions with IBM MQ Operator
CVE-2024-40681

7.5HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
7 September 2024

Summary

A security vulnerability in IBM MQ may allow an authenticated user with specific roles to circumvent established security measures, leading to the potential execution of unauthorized actions against the queue manager. This flaw affects several versions of IBM MQ, posing a risk to systems relying on this messaging platform.

Affected Version(s)

MQ Operator 2.0.26, 3.2.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.