CVE-2023-47745: IBM MQ Container information disclosure
IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores or transmits user credentials in plain clear text which can be read by a local user using a trace command. IBM X-Force ID: 272638.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47745?
CVE-2023-47745 is a high-severity vulnerability due to the exposure of user credentials in plain text.
How do I fix CVE-2023-47745?
To fix CVE-2023-47745, upgrade to the latest version of IBM MQ Operator that mitigates the exposure of user credentials.
What versions of IBM MQ Operator are affected by CVE-2023-47745?
CVE-2023-47745 affects IBM MQ Operator versions 2.0.0 LTS, 2.0.18 LTS, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, and 3.0.0 through 3.0.1.
What kind of data is exposed in CVE-2023-47745?
CVE-2023-47745 exposes user credentials, which can be read by a local user using a trace command.
Is there a workaround for CVE-2023-47745?
While the primary solution is to upgrade, temporarily restricting access to trace commands may serve as a workaround for CVE-2023-47745.