First published: Tue Apr 07 2020(Updated: )
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | >=9.1.0<9.1.5 | |
<=9.1 CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4338.
The severity of CVE-2020-4338 is medium.
A local attacker can exploit CVE-2020-4338 by including sensitive data within runmqras data.
Versions between 9.1.0 and 9.1.5 of IBM MQ are affected by CVE-2020-4338.
You can find more information about CVE-2020-4338 at the following references: [IBM X-Force ID: 177937](https://exchange.xforce.ibmcloud.com/vulnerabilities/177937) and [IBM Support](https://www.ibm.com/support/pages/node/6172539).