Improper error handling in IBM MQ - CVE-2024-31919

 

Improper error handling in IBM MQ - CVE-2024-31919

Published: June 27, 2024


Vulnerability identifier: #VU93444
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31919
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error caused by an error processing messages when an API Exit using MQBUFMH is used. A remote attacker can perform a denial of service (DoS) attack.


Affected software

IBM MQ
IBM MQ Operator
WebSphere Remote Server
IBM Sterling B2B Integrator
IBM Robotic Process Automation
Virtualization Engine TS7700 3957-VED
IBM Virtualization Engine TS7700 3948-VED
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2024-31919

Install updates from vendor's website.

IBM MQ - addressed in versions 9.0.0.25, 9.0.0.26, 9.1.0.22, 9.2.0.26, 9.3.0.20, 9.4
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.4
Virtualization Engine TS7700 3957-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM Virtualization Engine TS7700 3948-VED - addressed in versions 8.53.1.21 VTD_EXEC.405, 8.54.0.68 VTD_EXEC.405, 8.54.1.27 VTD_EXEC.405
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18

External References

Related Security Bulletins