First published: Fri Nov 05 2021(Updated: )
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | <=9.1 LTS | |
IBM MQ | <=9.1 CD | |
IBM MQ | <=9.0 LTS | |
IBM MQ | <=8.0 | |
IBM WebSphere MQ | <=7.5 | |
IBM MQ | >=8.0.0.0<8.0.0.14 | |
IBM MQ | >=9.0.0.0<9.0.0.9 | |
IBM MQ | >=9.1.0<9.1.5 | |
IBM MQ | >=9.1.0.0<9.1.0.5 | |
IBM WebSphere MQ | =7.5 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38949 is a vulnerability in IBM MQ that allows a local user to read user credentials stored in plain text.
CVE-2021-38949 vulnerability has a severity rating of 6.2 (medium).
IBM MQ versions 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS are affected by CVE-2021-38949 vulnerability.
A local user can exploit CVE-2021-38949 vulnerability by accessing and reading the plain text user credentials stored by IBM MQ.
Yes, IBM has released a fix for CVE-2021-38949 vulnerability. It is recommended to update to the latest version of IBM MQ to mitigate this vulnerability.