First published: Mon Jan 06 2020(Updated: )
IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | <=8.0 | |
IBM WebSphere MQ Appliance | <=9.1 LTS | |
IBM WebSphere MQ Appliance | <=9.1 CD | |
IBM WebSphere MQ Appliance | >=8.0.0.0<8.0.0.14 | |
IBM WebSphere MQ Appliance | >=9.1.0<9.1.4 | |
IBM WebSphere MQ Appliance | >=9.1.0.0<9.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4620 is considered a medium severity vulnerability due to its potential for local attackers to bypass security restrictions.
To fix CVE-2019-4620, it is recommended to update IBM MQ Appliance to a patched version as specified in IBM's advisories.
CVE-2019-4620 affects IBM MQ Appliance versions 8.0 through 8.0.0.14 and 9.0 through 9.1.0.4 depending on the release.
CVE-2019-4620 allows local attackers to bypass security restrictions via improper validation of environment variables.
CVE-2019-4620 is not exploitable remotely as it requires local access to the affected system.