PT-2020-17999 · Ibm · Ibm Mq+2

Published

2020-07-28

·

Updated

2021-07-21

·

CVE-2020-4319

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM MQ versions 8.0 through 9.1 IBM MQ Appliance versions 8.0 through 9.1 IBM MQ for HPE NonStop versions 8.0 through 9.1
Description The issue allows an authenticated user to obtain sensitive information under special circumstances due to a data leak from an error message within the pre-v7 pubsub logic.
Recommendations For IBM MQ versions 8.0 through 9.1, update to a version that includes the fix for this issue. For IBM MQ Appliance versions 8.0 through 9.1, update to a version that includes the fix for this issue. For IBM MQ for HPE NonStop versions 8.0 through 9.1, update to a version that includes the fix for this issue.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-4319

Affected Products

Ibm Mq
Ibm Mq Appliance
Ibm Mq For Hpe Nonstop