Incorrect Privilege Assignment in IBM MQ Operator - CVE-2024-40681

 

Incorrect Privilege Assignment in IBM MQ Operator - CVE-2024-40681

Published: September 16, 2024


Vulnerability identifier: #VU97306
CSH Severity: Low
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-40681
CWE-ID: CWE-266
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions. An authenticated user in a specifically defined role can bypass security restrictions and execute actions against the queue manager.


Affected software

IBM MQ Operator
WebSphere Remote Server
IBM MQ
IBM MQ Appliance
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2024-40681

Install updates from vendor's website.

IBM MQ Operator - addressed in versions 2.0.26, 3.2.4
IBM MQ - addressed in versions 9.1.0.23, 9.2.0.27, 9.3.0.21, 9.4.0.5
IBM MQ Appliance - addressed in versions 9.3.0.21, 9.4.0.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19

External References

Related Security Bulletins