CVE-2021-38986: Medium severity ibm websphere mq light vulnerability
IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 212942.
Other sources
IBM MQ Appliance does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38986?
The severity of CVE-2021-38986 is medium.
How does CVE-2021-38986 impact IBM MQ Appliance?
CVE-2021-38986 allows an authenticated user to impersonate another user on the system.
Which versions of IBM MQ Appliance are affected by CVE-2021-38986?
IBM MQ Appliance versions 9.2 CD and 9.2 LTS are affected by CVE-2021-38986.
How can I fix CVE-2021-38986?
To fix CVE-2021-38986, apply the necessary patches or updates provided by IBM.
Where can I find more information about CVE-2021-38986?
More information about CVE-2021-38986 can be found at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/212942) [Link 2](https://www.ibm.com/support/pages/node/6560032)