cbcvebase.
CVE-2024-51471
published 2024-12-19

CVE-2024-51471: IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to…

PriorityP422medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
0.32%
24.3th percentile
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size.

Affected

4 ranges
VendorProductVersion rangeFixed in
ibmmq_appliance
ibmmq_appliance9.3.0.0 – 9.3.0.26
ibmmq_appliance9.3.0.0 – 9.4.0.7
ibmmq_appliance9.4.0.0 – 9.4.0.7
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.