First published: Mon Jan 30 2023(Updated: )
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS is vulnerable to a denial of service attack caused by specially crafted PCF or MQSC messages. IBM X-Force ID: 240832.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ Appliance | >=9.2.0.0<9.2.0.8 | |
IBM MQ Appliance | >=9.2.0.0<9.2.5 | |
IBM MQ Appliance | =9.2.5 | |
IBM MQ Appliance | =9.2.5-cumulative_security_update_01 | |
IBM MQ Appliance | =9.2.5-cumulative_security_update_02 | |
IBM MQ Appliance | =9.2.5-cumulative_security_update_03 | |
IBM MQ Appliance | =9.3.0.0 | |
IBM MQ Appliance | =9.3.0.0 | |
IBM MQ Appliance | =9.3.1 | |
IBM MQ Appliance | <=9.3 LTS | |
IBM MQ Appliance | <=9.2 CD | |
IBM MQ Appliance | <=9.2 LTS | |
IBM MQ Appliance | <=9.3 CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-43902.
The severity of CVE-2022-43902 is high with a severity value of 7.5.
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS are affected.
This vulnerability can be exploited by sending specially crafted PCF or MQSC messages.
Please refer to the IBM support page for guidance on available fixes.