CVE-2020-4319Information Exposure via Error Message in IBM MQ Appliance

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 63.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 28
Latest updateMay 24

Description

IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDibm/mq_appliance8.08.0.0.15+2
CVEListV5ibm/mq_appliance8.0, 9.1.CD, 9.1.LTS+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r542-g4pm-8f6m: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 82022-05-24
CVEList
CVE-2020-4319: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 82020-07-28
CVE-2020-4319 — Information Exposure via Error Message | cvebase