Site icon API Security Blog

Security Bulletin: IBM MQ is affected by an issue in IBM WebSphere Application Server Liberty (CVE-2023-24998)

## Summary

A denial of service issue was identified in IBM WebSphere Application Server Liberty due to Apache Commons FileUpload, which IBM MQ ships and uses to supply IBM MQ Console and IBM MQ REST API functionality.

## Vulnerability Details

**CVEID: **[CVE-2023-24998]()
**DESCRIPTION: **Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by not limit the number of request parts to be processed in the file upload function. By sending a specially-crafted request with series of uploads, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/247895]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

## Affected Products and Versions

Affected Product(s) | Version(s)
—|—
IBM MQ | 9.1 LTS
IBM MQ | 9.2 LTS
IBM MQ | 9.3 LTS
IBM MQ | 9.2 CD
IBM MQ | 9.3 CD

The following installable MQ components are affected by the vulnerability:

– REST API and Console

If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see

## Remediation/Fixes

This issue was resolved under APAR IT43717

**IBM MQ 9.1 LTS**

[Apply cumulative security update 9.1.0.16]()

**IBM MQ 9.2 LTS**

[Apply fix pack 9.2.0.15]()

**IBM MQ 9.3 LTS**

[Apply cumulative security update 9.3.0.6]()

**IBM MQ 9.2 CD and 9.3 CD**

[Upgrade to IBM MQ Version 9.3.3]()

## Workarounds and Mitigations

None

##Read More

Exit mobile version