CVE-2024-31919

Severity
7.5HIGH
EPSS
0.3%
top 48.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28

Description

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5ibm/mq9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD
NVDibm/mq4 versions+3

🔴Vulnerability Details

2
CVEList
IBM MQ denial of service2024-06-28
GHSA
GHSA-8pf8-f3wp-vf64: IBM MQ 92024-06-28
CVE-2024-31919 (HIGH CVSS 7.5) | IBM MQ 9.0 LTS | cvebase.io