Bypass Security Restrictions with IBM MQ Operator
CVE-2024-40681
7.5HIGH
Summary
A security vulnerability in IBM MQ may allow an authenticated user with specific roles to circumvent established security measures, leading to the potential execution of unauthorized actions against the queue manager. This flaw affects several versions of IBM MQ, posing a risk to systems relying on this messaging platform.
Affected Version(s)
MQ Operator 2.0.26, 3.2.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved