IBM MQ
cpe:2.3:a:ibm:mq:*:*:*:*:*:*:*
- 9.4 LTS
- 9.4 CD
- 9.3 LTS
- 9.3 CD
A vulnerability in the IBM MQ web console in versions 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to access sensitive information. This occurs when a detailed technical error message is generated, potentially disclosing passwords or other confidential data.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including passwords, through the generation of detailed error messages that reveal such data.
Users can upgrade to IBM MQ version 9.4.1.1. For IBM MQ version 9.3 LTS, cumulative security update 9.3.0.26 is available. Users on IBM MQ version 9.4 LTS should apply cumulative security update 9.4.0.7.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.