CVE-2023-28514: IBM MQ information disclosure
IBM MQ 8.0, 9.0, and 9.1 could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace. IBM X-Force ID: 250398.
Other sources
IBM MQ could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28514?
CVE-2023-28514 is a vulnerability in IBM MQ that could allow a local user to obtain sensitive credential information when a detailed technical error message is returned in a stack trace.
Which versions of IBM MQ are affected by CVE-2023-28514?
IBM MQ 8.0, 9.0, and 9.1 are affected by CVE-2023-28514.
What is the severity of CVE-2023-28514?
The severity of CVE-2023-28514 is medium, with a CVSS score of 6.2.
How can a local user exploit CVE-2023-28514?
A local user can exploit CVE-2023-28514 by obtaining sensitive credential information from a detailed technical error message returned in a stack trace.
How can I fix CVE-2023-28514?
To fix CVE-2023-28514, update IBM MQ to a version that is not vulnerable.