Heap-based buffer overflow in IBM MQ Appliance - CVE-2024-25048
Published: May 2, 2024
Vulnerability identifier: #VU89108
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-25048
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper bounds checking. A remote attacker can overflow a buffer and execute arbitrary code on the system or cause the server to crash.
Affected software
IBM MQ Appliance
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM MQ Operator
IBM Sterling B2B Integrator
WebSphere Remote Server
IBM MQ for HPE NonStop
IBM MQ
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Supplied MQ Advanced Queue Manager Container images
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak
IBM MQ Operator
IBM Sterling B2B Integrator
WebSphere Remote Server
IBM MQ for HPE NonStop
IBM MQ
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Supplied MQ Advanced Queue Manager Container images
How to mitigate CVE-2024-25048
Install updates from vendor's website.
IBM MQ Appliance - addressed in versions 9.3.0.17, 9.3.5
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM MQ for HPE NonStop - update to 8.1.0.21
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM MQ - addressed in versions 9.0.0.24, 9.1.0.21, 9.2.0.25, 9.3.0.17, 9.3.5
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16
IBM MQ Operator - addressed in versions 2.0.21, 3.1.2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.3
IBM MQ for HPE NonStop - update to 8.1.0.21
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM MQ - addressed in versions 9.0.0.24, 9.1.0.21, 9.2.0.25, 9.3.0.17, 9.3.5
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.17-r1, 9.3.5.1-r1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16
External References
Related Security Bulletins
- Heap-based buffer overflow in IBM MQ for HPE NonStop
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Heap-based buffer overflow in IBM MQ
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Heap-based buffer overflow in IBM MQ Appliance
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in IBM System Storage Virtualization Engine TS7700
- IBM Sterling B2B Integrator update for IBM MQ