First published: Wed Sep 14 2022(Updated: )
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 235532."
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ Appliance | =9.2.0.0 | |
IBM MQ Appliance | =9.2.0.0 | |
IBM MQ Appliance | =9.3.0.0 | |
IBM MQ Appliance | =9.3.0.0 | |
IBM MQ Appliance | <=9.3 LTS | |
IBM MQ Appliance | <=9.2 CD | |
IBM MQ Appliance | <=9.2 LTS | |
IBM MQ Appliance | <=9.3 CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-40230 is medium.
The affected software for CVE-2022-40230 is IBM MQ Appliance versions 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS.
An authenticated user can exploit CVE-2022-40230 by impersonating another user on the system.
Yes, fixes for CVE-2022-40230 are available. Please refer to the IBM support page for more information.
You can find more information about CVE-2022-40230 on the IBM support page and the IBM X-Force ID page.