CVE-2021-38967: Code Injection
Published Nov 2, 2021
·Updated
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441.
Other sources
IBM MQ Appliance could allow a local privileged user to inject and execute malicious code.
— IBM
Affected Software
4 affected components
IBM MQ Appliance<=9.2 CD
IBM MQ Appliance<=9.2 LTS
IBM MQ Appliance=9.2.0.0
IBM MQ Appliance=9.2.0.0
Remediation
Patch Available
Event History
Nov 2, 2021
CVE Published
via IBM·12:00 AM
Nov 30, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38967.
2
What is the severity of CVE-2021-38967?
The severity of CVE-2021-38967 is high with a CVSS score of 8.2.
3
What is the affected software?
The affected software is the IBM MQ Appliance version 9.2 CD and 9.2 LTS.
4
What can a local privileged user do with this vulnerability?
A local privileged user can inject and execute malicious code.
5
Where can I find more information about CVE-2021-38967?
You can find more information about CVE-2021-38967 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/212441) and [Reference 2](https://www.ibm.com/support/pages/node/6512826).