Out-of-bounds write in AC15 - CVE-2024-0533
Published: September 18, 2024
Vulnerability details
The vulnerability allows a remote privileged user to compromise vulnerable system.
The vulnerability exists in the file /goform/SetOnlineDevName of the component Web-based Management Interface. A remote privileged user can send a specially crafted file, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
IBM MQ Appliance
How to mitigate CVE-2024-0533
IBM MQ Appliance - addressed in versions 9.3.0.21, 9.4.0.5