PT-2023-20585 · Ibm · Ibm Mq Certified Container

Published

2023-03-15

·

Updated

2023-03-19

·

CVE-2023-26284

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM MQ Certified Container versions 9.3.0.1 through 9.3.0.3 IBM MQ Certified Container versions 9.3.1.0 through 9.3.1.1
Description The issue allows authenticated users with cluster access to be granted administration access to the MQ console due to improper access controls.
Recommendations For IBM MQ Certified Container versions 9.3.0.1 through 9.3.0.3, update to a version outside of this range to resolve the issue. For IBM MQ Certified Container versions 9.3.1.0 through 9.3.1.1, update to a version outside of this range to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-26284

Affected Products

Ibm Mq Certified Container