Resource exhaustion in IBM MQ Appliance - CVE-2023-45177
Published: November 1, 2023
Vulnerability identifier: #VU82650
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45177
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote logic to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote logic can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM MQ Appliance
IBM supplied MQ Advanced container images
IBM MQ Operator
IBM Sterling Secure Proxy
IBM MQ for HPE NonStop
IBM MQ
IBM supplied MQ Advanced container images
IBM MQ Operator
IBM Sterling Secure Proxy
IBM MQ for HPE NonStop
IBM MQ
How to mitigate CVE-2023-45177
Install updates from vendor's website.
IBM MQ Appliance - addressed in versions 9.2.0.20, 9.3.0.10, 9.3.4
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM MQ for HPE NonStop - update to 8.1.0.17
IBM MQ - addressed in versions 9.0.0.21, 9.1.0.18, 9.2.0.20, 9.3.0.10, 9.3.4
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM MQ for HPE NonStop - update to 8.1.0.17
IBM MQ - addressed in versions 9.0.0.21, 9.1.0.18, 9.2.0.20, 9.3.0.10, 9.3.4
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1