First published: Mon Aug 05 2019(Updated: )
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill up the disk space of the underlying filesystem using the error logging service. IBM X-Force ID: 156398.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | >=9.1.0<=9.1.1 | |
IBM MQ | >=9.1.0.0<=9.1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4049 is medium with a severity value of 5.5.
CVE-2019-4049 is a vulnerability in IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 that allows a local user to fill up the disk space of the filesystem using the error logging service, causing a denial of service.
To fix CVE-2019-4049, update IBM MQ to a version that is not affected by the vulnerability.
The IBM X-Force ID of CVE-2019-4049 is 156398.
Yes, you can find references for CVE-2019-4049 at the following links: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/156398) and [Reference 2](https://www.ibm.com/support/docview.wss?uid=ibm10870490).