CVE-2024-54173: IBM MQ information disclosure
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
Other sources
IBM MQ reveals potentially sensitive information in trace files that could be read by a local user when webconsole trace is enabled.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54173?
The severity of CVE-2024-54173 is classified as medium due to the potential for local users to access sensitive information in trace files.
How do I fix CVE-2024-54173?
To fix CVE-2024-54173, disable the webconsole trace feature to prevent sensitive information from being exposed.
Which versions of IBM MQ are affected by CVE-2024-54173?
CVE-2024-54173 affects IBM MQ versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD.
How can local users exploit CVE-2024-54173?
Local users can exploit CVE-2024-54173 by reading sensitive information stored in trace files when the webconsole trace is enabled.
What type of information is exposed in CVE-2024-54173?
CVE-2024-54173 exposes potentially sensitive information that can include configuration details and authentication data.