Information exposure through externally-generated error message in IBM MQ - CVE-2024-35156
Published: June 27, 2024
Vulnerability identifier: #VU93443
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35156
CWE-ID: CWE-211
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application while handling error conditions. A remote attacker can obtain sensitive information on the system.
Affected software
IBM MQ
IBM MQ Operator
WebSphere Remote Server
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM MQ Operator
WebSphere Remote Server
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2024-35156
Install updates from vendor's website.
IBM MQ - addressed in versions 9.3.0.20, 9.4
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18