CVE-2023-28950: IBM MQ information disclosure
Published May 19, 2023
·Updated
IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled. IBM X-Force ID: 251358.
Affected Software
13 affected components
IBM MQ=8.0.0.0
IBM MQ=9.0.0.0
IBM MQ=9.1.0.0
IBM MQ=9.2.0
IBM MQ=9.2.0
IBM MQ=9.3.0
IBM MQ=9.3.0
HP HP-UX
IBM AIX
IBM i
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
May 19, 2023
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-28950.
2
What versions of IBM MQ are affected by this vulnerability?
IBM MQ versions 8.0, 9.0, 9.1, 9.2, and 9.3 are affected.
3
What is the severity of CVE-2023-28950?
The severity of CVE-2023-28950 is medium with a severity value of 5.5.
4
How can sensitive user information be disclosed from a trace file in IBM MQ?
Sensitive user information can be disclosed from a trace file if the trace functionality has been enabled.
5
How can I fix CVE-2023-28950 in IBM MQ?
To fix CVE-2023-28950 in IBM MQ, you should apply the necessary security patches provided by IBM.