CVE-2020-4592IBM MQ Appliance vulnerability

3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 67.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMay 24

Description

IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/mq_appliance9.1.CD, 9.1.LTS+1
NVDibm/mq_appliance9.1.0.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w986-fvg4-hvqg: IBM MQ Appliance 92022-05-24
CVEList
CVE-2020-4592: IBM MQ Appliance 92020-11-18
CVE-2020-4592 — IBM MQ Appliance vulnerability | cvebase