CVE-2021-39000: Infoleak
Published Nov 23, 2021
·Updated
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics. IBM X-Force ID: 213215.
Other sources
IBM MQ could allow a local attacker to obtain sensitive information by inclusion of sensitive data within diagnostics.
— IBM
Affected Software
4 affected components
IBM MQ Appliance<=9.2 CD
IBM MQ Appliance<=9.2 LTS
IBM MQ Appliance=9.2.0.0
IBM MQ Appliance=9.2.0.0
Remediation
Patch Available
Event History
Nov 23, 2021
CVE Published
via IBM·12:00 AM
Nov 30, 2021
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this IBM MQ Appliance vulnerability?
The vulnerability ID for this IBM MQ Appliance vulnerability is CVE-2021-39000.
2
What is the severity of CVE-2021-39000?
The severity of CVE-2021-39000 is medium with a CVSS score of 5.9.
3
How could a local attacker exploit this vulnerability?
A local attacker could exploit this vulnerability by including sensitive data within diagnostics.
4
Which versions of IBM MQ Appliance are affected by CVE-2021-39000?
IBM MQ Appliance versions 9.2 CD and 9.2 LTS are affected by CVE-2021-39000.
5
Is there a fix available for CVE-2021-39000?
Please refer to the IBM Support page for information on available fixes for CVE-2021-39000.