Information exposure through externally-generated error message in IBM MQ - CVE-2024-35155
Published: June 27, 2024
Vulnerability identifier: #VU93445
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-35155
CWE-ID: CWE-211
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the IBM MQ Console while handling error conditions. A remote attacker can obtain sensitive information on the system.
Affected software
IBM MQ
IBM MQ Operator
WebSphere Remote Server
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM MQ Operator
WebSphere Remote Server
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2024-35155
Install updates from vendor's website.
IBM MQ - addressed in versions 9.3.0.20, 9.4
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
IBM MQ Operator - addressed in versions 9.3.0.20-r1, 9.4.0.0-r2
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18