First published: Fri May 19 2023(Updated: )
IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled. IBM X-Force ID: 251358.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM MQ | =8.0.0.0 | |
IBM MQ | =9.0.0.0 | |
IBM MQ | =9.1.0.0 | |
IBM MQ | =9.2.0 | |
IBM MQ | =9.2.0 | |
IBM MQ | =9.3.0 | |
IBM MQ | =9.3.0 | |
HP HP-UX | ||
IBM AIX | ||
IBM i | ||
Linux Linux kernel | ||
Microsoft Windows | ||
Oracle Solaris |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-28950.
IBM MQ versions 8.0, 9.0, 9.1, 9.2, and 9.3 are affected.
The severity of CVE-2023-28950 is medium with a severity value of 5.5.
Sensitive user information can be disclosed from a trace file if the trace functionality has been enabled.
To fix CVE-2023-28950 in IBM MQ, you should apply the necessary security patches provided by IBM.