SB2023030652 - Improper authorization in IBM Supplied MQ Advanced Queue Manager Container images
Published: March 6, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Authorization (CVE-ID: CVE-2023-26284)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to improper authorization. All users authenticated with the cluster are granted administration access to the MQ Console, without checking IAM access rights.
Remediation
Install update from vendor's website.