CVE-2022-42436: IBM MQ information disclosure
Published Feb 1, 2023
·Updated
IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files. IBM X-Force ID: 238206.
Other sources
IBM MQ Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files.
Affected Software
22 affected components
IBM MQ<=8.0
IBM MQ<=9.0 LTS
IBM MQ<=9.1 CD
IBM MQ<=9.1 LTS
IBM MQ<=9.2 CD
IBM MQ<=9.2 LTS
IBM MQ<=9.3 CD
IBM MQ<=9.3 LTS
IBM MQ=8.0.0.0
IBM MQ=9.0.0.0
IBM MQ=9.1.0
IBM MQ=9.1.0.0
IBM MQ=9.2.0
IBM MQ=9.2.0
IBM MQ=9.3.0
IBM MQ=9.3.0
IBM AIX
IBM i
IBM Linux On Ibm Z
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Feb 1, 2023
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Feb 8, 2023
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-42436.
2
What is the title of this vulnerability?
The title of this vulnerability is 'IBM MQ Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files.'
3
What is the severity of CVE-2022-42436?
The severity of CVE-2022-42436 is medium.
4
Which versions of IBM MQ are affected by this vulnerability?
IBM MQ versions 8.0.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 are affected by this vulnerability.
5
How can a local user obtain sensitive information from diagnostic files in IBM MQ Managed File Transfer?
A local user can obtain sensitive information from diagnostic files in IBM MQ Managed File Transfer due to a vulnerability.