CVE-2023-26284: IBM MQ Certified Container improper access controls
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
Other sources
IBM MQ Certified Container could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26284?
CVE-2023-26284 has been assessed to have a moderate severity level due to the potential for unauthorized administration access.
How do I fix CVE-2023-26284?
To fix CVE-2023-26284, update your IBM MQ Certified Container to a version that is not affected, specifically above version 9.3.0.4 or 9.3.1.1.
Who is affected by CVE-2023-26284?
CVE-2023-26284 affects users of IBM MQ Certified Container versions 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1.
What is the impact of CVE-2023-26284?
The impact of CVE-2023-26284 is that authenticated users could be granted unauthorized administration access to the MQ console.
Is there a workaround for CVE-2023-26284?
Currently, there are no documented workarounds for CVE-2023-26284, and upgrading to a fixed version is the recommended solution.