Security Bulletin: IBM MQ Appliance is affected by multiple AngularJS vulnerabilities
Discription

## Summary

IBM MQ Appliance has resolved multiple AngularJS vulnerabilities (CVE-2023-26117, CVE-2023-26116, CVE-2023-26118, CVE-2022-25869, CVE-2022-25844).

## Vulnerability Details

**CVEID: **[CVE-2023-26117]()
**DESCRIPTION: **AngularJS is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the $resource service. By providing specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/251496]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

**CVEID: **[CVE-2023-26116]()
**DESCRIPTION: **AngularJS is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the angular.copy() utility function. By providing specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/251497]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

**CVEID: **[CVE-2023-26118]()
**DESCRIPTION: **AngularJS is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the input[url] functionality. By providing specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/251494]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

**CVEID: **[CVE-2022-25869]()
**DESCRIPTION: **Node.js angular module is vulnerable to cross-site scripting, caused by improper validation of user-supplied input when caching pages using Internet Explorer. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVSS Base score: 4.2
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/231374]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N)

**CVEID: **[CVE-2022-25844]()
**DESCRIPTION: **Node.js Angular module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in posPre: ‘ ‘.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre. By sending a specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: [ https://exchange.xforce.ibmcloud.com/vulnerabilities/225115]() for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

## Affected Products and Versions

Affected Product(s) | Version(s)
—|—
IBM MQ Appliance | 9.2 CD
IBM MQ Appliance | 9.2 LTS

## Remediation/Fixes

**IBM strongly recommends addressing the vulnerability now.**

**IBM MQ Appliance version 9.2 LTS**

Upgrade to [IBM MQ Appliance 9.3.0](), or later firmware.

**IBM MQ Appliance version 9.2 CD**

Upgrade to [IBM MQ Appliance 9.3.0](), or later firmware.

## Workarounds and Mitigations

If not ready to upgrade to IBM MQ Appliance 9.3 the New Web Console (which is the default web console for IBM MQ Appliance 9.2) is not vulnerable.

For instructions on switching from Dashboard Web Console to New Web Console see

##Read More

Back to Main

Subscribe for the latest news: