First published: Wed Nov 24 2021(Updated: )
IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | >=9.2.0<9.2.0.4 | |
IBM MQ | >=9.2.0<9.2.5 | |
<=9.2 CD | ||
<=9.2 LTS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-38986 is medium.
CVE-2021-38986 allows an authenticated user to impersonate another user on the system.
IBM MQ Appliance versions 9.2 CD and 9.2 LTS are affected by CVE-2021-38986.
To fix CVE-2021-38986, apply the necessary patches or updates provided by IBM.
More information about CVE-2021-38986 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/212942) [Link 2](https://www.ibm.com/support/pages/node/6560032)