Improper error handling in IBM MQ - CVE-2024-35116

 

Improper error handling in IBM MQ - CVE-2024-35116

Published: June 27, 2024


Vulnerability identifier: #VU93442
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35116
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error applying configuration changes. A remote attacker can send specially crafted requests to the application and perform a denial of service (DoS) attack.


Affected software

IBM MQ
IBM MQ Operator
WebSphere Remote Server
IBM Sterling B2B Integrator
IBM MQ for HPE NonStop
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Virtualization Engine TS7700 3948-VED
IBM MQ Appliance
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2024-35116

Install updates from vendor's website.

IBM MQ - addressed in versions 9.0.0.26, 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.4
IBM MQ for HPE NonStop - update to 8.1.0.25
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM MQ Appliance - addressed in versions 9.3.0.20, 9.3.5.2
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18

External References

Related Security Bulletins