CVE-2023-26285: IBM MQ denial of service
Published Apr 27, 2023
·Updated
IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow a remote attacker to cause a denial of service due to an error processing invalid data. IBM X-Force ID: 248418.
Other sources
IBM MQ could allow a remote attacker to cause a denial of service due to an error processing invalid data.
Affected Software
12 affected components
IBM MQ Appliance<=9.3 LTS
IBM MQ Appliance<=9.2 CD
IBM MQ Appliance<=9.2 LTS
IBM MQ Appliance<=9.3 CD
IBM MQ Appliance>=9.2.0.0<9.2.0.11
IBM MQ Appliance>=9.2.0.0<9.2.5.7
IBM MQ Appliance>=9.3.0.0<9.3.0.5
IBM MQ Appliance>=9.3.0.0<9.3.2.1
IBM MQ Appliance<=9.2.CD
IBM MQ Appliance<=9.2.LTS
IBM MQ Appliance<=9.3.LTS
IBM MQ Appliance<=9.3.CD
Remediation
Patch Available
Event History
Apr 27, 2023
CVE Published
via IBM·12:00 AM
Apr 28, 2023
Advisory Published
12:00 AM
May 5, 2023
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
04:15 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-26285.
2
What is the severity rating of CVE-2023-26285?
The severity rating of CVE-2023-26285 is medium (5.9).
3
What is the affected software?
The affected software is IBM MQ Appliance versions 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS.
4
What is the impact of this vulnerability?
This vulnerability can cause a denial of service.
5
Are there any fixes or patches available for this vulnerability?
Please refer to IBM's support page for information on available fixes and patches for CVE-2023-26285.