Allocation of Resources Without Limits or Throttling in IBM MQ Operator - CVE-2024-40680
Published: September 16, 2024
Vulnerability identifier: #VU97305
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H]
CVE-ID: CVE-2024-40680
CWE-ID: CWE-770
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
IBM MQ Operator
WebSphere Remote Server
IBM MQ
IBM MQ Appliance
Robotic Process Automation for Cloud Pak
WebSphere Remote Server
IBM MQ
IBM MQ Appliance
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2024-40680
Install updates from vendor's website.
IBM MQ Operator - addressed in versions 2.0.26, 3.2.4
IBM MQ - update to 9.4.0.5
IBM MQ Appliance - update to 9.4.0.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
IBM MQ - update to 9.4.0.5
IBM MQ Appliance - update to 9.4.0.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- Allocation of resources without limits or throttling in IBM MQ
- Allocation of resources without limits or throttling in IBM MQ Appliance
- Multiple vulnerabilities in IBM WebSphere Remote Server
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak