First published: Tue Feb 28 2023(Updated: )
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ Advanced Queue Manager Container | <=9.3.0.1-r1 till 9.3.0.1-r4(including), 9.3.0.3-r1, 9.3.1.0-r1 till v9.3.1.0-r3(including) and 9.3.1.1-r1 | |
IBM MQ Advanced | >=9.3.0.1<9.3.0.4 | |
IBM MQ Advanced | >=9.3.1.0<9.3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26284 has been assessed to have a moderate severity level due to the potential for unauthorized administration access.
To fix CVE-2023-26284, update your IBM MQ Certified Container to a version that is not affected, specifically above version 9.3.0.4 or 9.3.1.1.
CVE-2023-26284 affects users of IBM MQ Certified Container versions 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1.
The impact of CVE-2023-26284 is that authenticated users could be granted unauthorized administration access to the MQ console.
Currently, there are no documented workarounds for CVE-2023-26284, and upgrading to a fixed version is the recommended solution.