First published: Sat Apr 27 2024(Updated: )
IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. IBM X-Force ID: 283137.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | <=9.3 LTS | |
IBM WebSphere MQ Appliance | <=9.3 CD |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25048 is a critical vulnerability due to its potential for remote code execution and server crashes.
To fix CVE-2024-25048, update the IBM MQ Appliance to the latest version that addresses this vulnerability.
CVE-2024-25048 can allow a remote authenticated attacker to perform arbitrary code execution or crash the server.
CVE-2024-25048 affects IBM MQ Appliance versions 9.3 CD and 9.3 LTS.
CVE-2024-25048 was identified by IBM X-Force and is assigned an X-Force ID of 283137.