Resource exhaustion in IBM MQ Appliance - CVE-2023-45177

 

Resource exhaustion in IBM MQ Appliance - CVE-2023-45177

Published: November 1, 2023


Vulnerability identifier: #VU82650
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45177
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote logic to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote logic can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

IBM MQ Appliance
IBM supplied MQ Advanced container images
IBM MQ Operator
IBM Sterling Secure Proxy
IBM MQ for HPE NonStop
IBM MQ

How to mitigate CVE-2023-45177

Install updates from vendor's website.

IBM MQ Appliance - addressed in versions 9.2.0.20, 9.3.0.10, 9.3.4
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM MQ for HPE NonStop - update to 8.1.0.17
IBM MQ - addressed in versions 9.0.0.21, 9.1.0.18, 9.2.0.20, 9.3.0.10, 9.3.4
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1

External References

Related Security Bulletins