Input validation error in IBM MQ Appliance - CVE-2024-25016

 

Input validation error in IBM MQ Appliance - CVE-2024-25016

Published: March 5, 2024


Vulnerability identifier: #VU87128
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25016
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect buffering logic. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

IBM MQ Appliance
IBM Virtualization Engine TS7700 3948-VED
Integration Bus for z/OS
Robotic Process Automation for Cloud Pak
IBM Intelligent Operations Center
IBM MQ Operator
App Connect Enterprise Certified Container
IBM Sterling Secure Proxy
IBM MQ
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Supplied MQ Advanced Queue Manager Container images
IBM DataPower Gateway
IBM App Connect Enterprise

How to mitigate CVE-2024-25016

Install updates from vendor's website.

IBM MQ Appliance - addressed in versions 9.3.0.16, 9.3.5
IBM MQ Operator - addressed in versions 2.0.19, 3.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.19, 12.0.12-r2, 12.2.0
IBM Sterling Secure Proxy - addressed in versions 6.0.3.1, 6.1.0.1, 6.2.0.0 ifix 01
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM MQ - addressed in versions 9.0.0.23, 9.1.0.20, 9.2.0.22, 9.3.0.16, 9.3.5
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r1, 9.3.3.3-r2, 9.3.5.0-r1
Integration Bus for z/OS - update to 10.1.0.3
IBM DataPower Gateway - addressed in versions 10.5.0.15, 10.6.0.3, 10.6.2
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.12.0
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16

External References

Related Security Bulletins