CVE-2020-4338: Infoleak
IBM MQ 9.1.4 could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data. IBM X-Force ID: 177937.
Other sources
IBM MQ could allow a local attacker to obtain sensitive information by inclusion of sensitive data within runmqras data.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-4338.
What is the severity of CVE-2020-4338?
The severity of CVE-2020-4338 is medium.
How can a local attacker exploit CVE-2020-4338?
A local attacker can exploit CVE-2020-4338 by including sensitive data within runmqras data.
Which versions of IBM MQ are affected by CVE-2020-4338?
Versions between 9.1.0 and 9.1.5 of IBM MQ are affected by CVE-2020-4338.
Where can I find more information about CVE-2020-4338?
You can find more information about CVE-2020-4338 at the following references: [IBM X-Force ID: 177937](https://exchange.xforce.ibmcloud.com/vulnerabilities/177937) and [IBM Support](https://www.ibm.com/support/pages/node/6172539).