CVE-2022-22356: Medium severity IBM MQ Appliance vulnerability
IBM DataPower Gateway could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts.
Other sources
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-22356.
What is the affected software of this vulnerability?
The affected software of this vulnerability is IBM MQ Appliance 9.2 CD and 9.2 LTS.
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts.
Is there any additional information available about this vulnerability?
Yes, you can find additional information about this vulnerability at the following references: [IBM X-Force ID: 220487](https://exchange.xforce.ibmcloud.com/vulnerabilities/220487) and [IBM Support Site](https://www.ibm.com/support/pages/node/6564711).