First published: Wed Apr 26 2023(Updated: )
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are vulnerable to a denial of service attack when processing configuration files. IBM X-Force ID: 244216.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Light | <=9.2.CD | |
IBM WebSphere MQ Light | <=9.3.CD | |
IBM WebSphere MQ Light | <=9.3.LTS | |
IBM WebSphere MQ Light | <=9.2 CD | |
IBM WebSphere MQ Light | <=9.3 CD | |
IBM WebSphere MQ Light | <=9.3 LTS | |
IBM MQ Appliance Firmware | >=9.2.0.0<9.3.2 | |
IBM MQ Appliance Firmware | >=9.3.0.0<9.3.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22874 is a vulnerability in IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS that allows for a denial of service attack when processing configuration files.
CVE-2023-22874 has a severity rating of medium.
IBM MQ Clients 9.2 CD, 9.3 CD, and 9.3 LTS are affected by CVE-2023-22874.
To fix CVE-2023-22874, update IBM MQ Clients to a version that is not vulnerable.
You can find more information about CVE-2023-22874 on the IBM support pages, IBM X-Force exchange, and CVE Mitre.