Heap-based buffer overflow in IBM MQ Appliance - CVE-2024-25048

 

Heap-based buffer overflow in IBM MQ Appliance - CVE-2024-25048

Published: May 2, 2024


Vulnerability identifier: #VU89108
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25048
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper bounds checking. A remote attacker can overflow a buffer and execute arbitrary code on the system or cause the server to crash.


Affected software

IBM MQ Appliance
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM MQ Operator
IBM Sterling B2B Integrator
WebSphere Remote Server
IBM MQ for HPE NonStop
IBM MQ
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Supplied MQ Advanced Queue Manager Container images

How to mitigate CVE-2024-25048

Install updates from vendor's website.

IBM MQ Appliance - addressed in versions 9.3.0.17, 9.3.5
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM MQ for HPE NonStop - update to 8.1.0.21
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM MQ - addressed in versions 9.0.0.24, 9.1.0.21, 9.2.0.25, 9.3.0.17, 9.3.5
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16

External References

Related Security Bulletins