CVE-2020-4267Missing Release of Memory after Effective Lifetime in IBM MQ Appliance

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 58.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 24
Latest updateMay 24

Description

IBM MQ and MQ Appliance 8.0, 9.1 LTS, and 9.1 CD could allow an authenticated user cause a denial of service due to a memory leak. IBM X-Force ID: 175840.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

NVDibm/mq_appliance9.1.09.1.5
CVEListV5ibm/mq_appliance22 versions+21
NVDibm/mq8.0.0.08.0.0.14+1

🔴Vulnerability Details

2
GHSA
GHSA-pvcg-m8c9-58wj: IBM MQ and MQ Appliance 82022-05-24
CVEList
CVE-2020-4267: IBM MQ and MQ Appliance 82020-04-24
CVE-2020-4267 — IBM MQ Appliance vulnerability | cvebase