CVE-2021-38999: Infoleak
Published Nov 23, 2021
·Updated
IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trace.
Affected Software
4 affected components
IBM MQ Appliance<=9.2 CD
IBM MQ Appliance<=9.2 LTS
IBM MQ Appliance=9.2.0.0
IBM MQ Appliance=9.2.0.0
Remediation
Patch Available
Event History
Nov 23, 2021
CVE Published
via IBM·12:00 AM
Nov 30, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-38999.
2
What is the severity of CVE-2021-38999?
The severity of CVE-2021-38999 is medium.
3
How does CVE-2021-38999 impact IBM MQ Appliance?
CVE-2021-38999 allows a local attacker to obtain sensitive information by including sensitive data within trace.
4
Which versions of IBM MQ Appliance are affected by CVE-2021-38999?
Versions 9.2 CD and 9.2 LTS of IBM MQ Appliance are affected by CVE-2021-38999.
5
How can I fix CVE-2021-38999?
To fix CVE-2021-38999, IBM recommends applying the necessary patches and updates provided by IBM.