CVE-2019-4141Missing Release of Memory after Effective Lifetime in IBM Websphere MQ

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 42.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 27
Latest updateMay 24

Description

IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDibm/websphere_mq7.1.0.07.1.0.9+5
NVDibm/websphere_mq_appliance8.0.0.08.0.0.11+2
CVEListV5ibm/mq43 versions+42

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wvmr-83rm-r93m: IBM MQ 72022-05-24
CVEList
CVE-2019-4141: IBM MQ 72019-09-27

💥Exploits & PoCs

1
Exploit-DB
WordPress 5.0.0 - Image Remote Code Execution2021-02-01
CVE-2019-4141 — IBM Websphere MQ vulnerability | cvebase