CVE-2022-40230: Medium severity IBM MQ Appliance vulnerability
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
Other sources
IBM MQ Appliance does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40230?
The severity of CVE-2022-40230 is medium.
What is the affected software for CVE-2022-40230?
The affected software for CVE-2022-40230 is IBM MQ Appliance versions 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS.
How can an authenticated user exploit CVE-2022-40230?
An authenticated user can exploit CVE-2022-40230 by impersonating another user on the system.
Are there any fixes available for CVE-2022-40230?
Yes, fixes for CVE-2022-40230 are available. Please refer to the IBM support page for more information.
Where can I find more information about CVE-2022-40230?
You can find more information about CVE-2022-40230 on the IBM support page and the IBM X-Force ID page.