CVE-2021-38949: Medium severity ibm websphere mq light vulnerability
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
Other sources
IBM MQ stores user credentials in plain clear text which can be read by a local user.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-38949 vulnerability?
CVE-2021-38949 is a vulnerability in IBM MQ that allows a local user to read user credentials stored in plain text.
How severe is CVE-2021-38949 vulnerability?
CVE-2021-38949 vulnerability has a severity rating of 6.2 (medium).
Which versions of IBM MQ are affected by CVE-2021-38949 vulnerability?
IBM MQ versions 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS are affected by CVE-2021-38949 vulnerability.
How can a local user exploit CVE-2021-38949 vulnerability?
A local user can exploit CVE-2021-38949 vulnerability by accessing and reading the plain text user credentials stored by IBM MQ.
Is there a fix available for CVE-2021-38949 vulnerability?
Yes, IBM has released a fix for CVE-2021-38949 vulnerability. It is recommended to update to the latest version of IBM MQ to mitigate this vulnerability.