PT-2024-25427 · Ibm · Websphere Mq

CVE-2024-3367

·

Published

2024-04-16

·

Updated

2024-12-05

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 2.0.0 through 2.1.0 Checkmk versions prior to 2.2.0p26 Checkmk versions prior to 2.3.0b5
Description The issue allows a local attacker to inject an argument to runmqsc, potentially due to an untrusted data vulnerability in the websphere mq agent plugin.
Recommendations For Checkmk versions 2.0.0 through 2.1.0, upgrade Checkmk to the latest version. For Checkmk versions prior to 2.2.0p26, upgrade Checkmk to the latest version. For Checkmk versions prior to 2.3.0b5, upgrade Checkmk to the latest version. As a general mitigation measure, identify affected systems, review plugin usage and permissions.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3367

Affected Products

Websphere Mq