CVE-2020-4465Classic Buffer Overflow in IBM MQ Appliance

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 32.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 28
Latest updateMay 24

Description

IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS is vulnerable to a buffer overflow vulnerability due to an error within the channel processing code. A remote attacker could overflow the buffer using an older client and cause a denial of service. IBM X-Force ID: 181562.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDibm/mq_appliance8.08.0.0.15+2
CVEListV5ibm/mq_appliance8.0, 9.1.CD, 9.1.LTS+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xr77-4rxw-6357: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 82022-05-24
CVEList
CVE-2020-4465: IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 82020-07-28
CVE-2020-4465 — Classic Buffer Overflow in IBM | cvebase