CVE-2020-4592: Medium severity IBM MQ Appliance vulnerability
IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
Other sources
IBM MQ could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-4592?
CVE-2020-4592 is a vulnerability that exists in IBM MQ Appliance 9.1.CD and LTS, which allows an authenticated user under nondefault configuration to cause a data corruption attack due to an error when using segmented messages.
What software is affected by CVE-2020-4592?
IBM MQ Appliance 9.1.CD and LTS are affected by CVE-2020-4592.
How severe is CVE-2020-4592?
CVE-2020-4592 has a severity rating of 6.5 (medium).
How can an authenticated user exploit CVE-2020-4592?
An authenticated user can exploit CVE-2020-4592 by causing a data corruption attack under a nondefault configuration when using segmented messages.
Is there a fix available for CVE-2020-4592?
Yes, IBM has provided a fix for CVE-2020-4592. Please refer to the IBM support page for more information.