CVE-2024-51471Out-of-bounds Read in IBM MQ Appliance

CWE-125Out-of-bounds Read3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.2%
top 59.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 19

Description

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

NVDibm/mq_appliance9.3.0.09.3.0.26+2
CVEListV5ibm/mq_appliance9.3 LTS, 9.3 CD, 9.4 LTS

🔴Vulnerability Details

2
GHSA
GHSA-2p6g-86q5-vxxh: IBM MQ Appliance 92024-12-19
CVEList
IBM MQ Appliance denial of service2024-12-19
CVE-2024-51471 — Out-of-bounds Read in IBM MQ Appliance | cvebase