CVE-2020-4375: High severity IBM MQ Appliance vulnerability
IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue. IBM X-Force ID: 179080.
Other sources
IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4375?
CVE-2020-4375 is a vulnerability in IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS that could allow an attacker to cause a denial of service due to a memory leak caused by an error creating a dynamic queue.
What is the severity of CVE-2020-4375?
CVE-2020-4375 has a severity rating of 7.5 (high).
Which products are affected by CVE-2020-4375?
IBM MQ, IBM MQ Appliance, IBM MQ for HPE NonStop 8.0, 9.1 CD, and 9.1 LTS are affected by CVE-2020-4375.
How can an attacker exploit CVE-2020-4375?
An attacker can exploit CVE-2020-4375 by causing a denial of service through a memory leak resulting from an error creating a dynamic queue.
Is there a fix available for CVE-2020-4375?
Yes, IBM has released fixes for CVE-2020-4375. Please refer to the IBM support page for more information.