Inclusion of Sensitive Information in Log Files in IBM MQ - CVE-2023-28514
Published: April 28, 2023
Vulnerability identifier: #VU75591
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28514
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into trace files. A local user can read the trace files and gain access to sensitive data.
Affected software
IBM MQ
IBM MQ for HPE NonStop
IBM MQ for HPE NonStop
How to mitigate CVE-2023-28514
Install updates from vendor's website.
IBM MQ - addressed in versions 9.0.0.16, 9.1.4.0
IBM MQ for HPE NonStop - update to 8.1.0.16
IBM MQ for HPE NonStop - update to 8.1.0.16