Site icon API Security Blog

Security Bulletin: IBM MQ is affected by a vulnerability in the IBM Runtime Environment, Java Technology Edition.

Summary An issue was identified with IBM Runtime Environment, Java Technology Edition, Version 8 which is shipped with IBM MQ for Solaris. Vulnerability Details CVEID: CVE-2023-22045 DESCRIPTION: An unspecified vulnerability in Java SE related to the VM component could allow a remote attacker to cause low confidentiality impacts. CVSS Base score: 3.7 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/261047 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) Affected Products and Versions Affected Product(s) | Version(s) —|— IBM MQ | 9.0 LTS IBM MQ | 9.1 LTS The following installable MQ components are affected by the vulnerability: – Java JRE – Java messaging – AMQP Service – Managed File Transfer – REST API and Console If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins Remediation/Fixes This issue was addressed under APAR IT44623 IBM MQ version 9.0 LTS for Solaris Apply Cumulative Security Update 9.0.0.21 IBM MQ version 9.1 LTS for Solaris Apply Cumulative Security Update 9.1.0.18 Workarounds and Mitigations…Read More

Exit mobile version