CVE-2019-4655: Medium severity ibm websphere mq appliance vulnerability
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine. IBM X-Force ID: 170966.
Other sources
IBM MQ is vulnerable to a denial of service attack that would allow an authenticated user to reset client connections due to an error within the Data Conversion routine.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-4655?
CVE-2019-4655 is a vulnerability in IBM MQ that allows an authenticated user to reset client connections, leading to a denial of service attack.
How severe is CVE-2019-4655?
CVE-2019-4655 has a severity score of 4.3, which is considered medium.
Which versions of IBM MQ are affected by CVE-2019-4655?
IBM MQ versions 9.1.0.0 to 9.1.4 are affected by CVE-2019-4655.
How can an authenticated user exploit CVE-2019-4655?
An authenticated user can exploit CVE-2019-4655 by using a specially crafted request to reset client connections and cause a denial of service.
Is there a fix available for CVE-2019-4655?
Yes, IBM has released fixes for CVE-2019-4655. It is recommended to update to a fixed version of IBM MQ.