Summary IBM MQ has addressed a denial of service vulnerability caused by an error processing messages when an API Exit using MQBUFMH is used. Vulnerability Details CVEID: CVE-2024-31919 DESCRIPTION: IBM MQ, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. CVSS Base score: 5.9 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/290259 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s) | Version(s) —|— IBM MQ | 9.0 LTS IBM MQ | 9.1 LTS IBM MQ | 9.2 LTS IBM MQ | 9.3 LTS IBM MQ | 9.3 CD The following installable MQ components are affected by the vulnerability: – Server If you are running any of these listed components, please apply the remediation/fixes as described below. For more information on the definitions of components used in this list see https://www.ibm.com/support/pages/installable-component-names-used-ibm-mq-security-bulletins Remediation/Fixes This issue was addressed under APAR IT45510. IBM MQ version 9.0 LTS Apply Cumulative Security Update 9.0.0.26 IBM MQ version 9.1 LTS Apply Cumulative Security Update 9.1.0.22 IBM MQ version 9.2 LTS Apply Cumulative Security Update 9.2.0.26 IBM MQ version 9.3 LTS Apply Fix Pack 9.3.0.20 IBM MQ version 9.3 CD Upgrade to IBM MQ version 9.4 Workarounds and Mitigations…Read More
