Incorrect Privilege Assignment in IBM MQ Operator - CVE-2024-40681
Published: September 16, 2024
Vulnerability identifier: #VU97306
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40681
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. An authenticated user in a specifically defined role can bypass security restrictions and execute actions against the queue manager.
Affected software
IBM MQ Operator
WebSphere Remote Server
IBM MQ
IBM MQ Appliance
Robotic Process Automation for Cloud Pak
WebSphere Remote Server
IBM MQ
IBM MQ Appliance
Robotic Process Automation for Cloud Pak
How to mitigate CVE-2024-40681
Install updates from vendor's website.
IBM MQ Operator - addressed in versions 2.0.26, 3.2.4
IBM MQ - addressed in versions 9.1.0.23, 9.2.0.27, 9.3.0.21, 9.4.0.5
IBM MQ Appliance - addressed in versions 9.3.0.21, 9.4.0.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
IBM MQ - addressed in versions 9.1.0.23, 9.2.0.27, 9.3.0.21, 9.4.0.5
IBM MQ Appliance - addressed in versions 9.3.0.21, 9.4.0.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19