Vulnerability Name:
CVE-2019-4568 (CCN-166629)
Assigned:
2019-01-03
Published:
2020-01-24
Updated:
2021-07-21
Summary:
IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause a denial of service when receiving data on the channel. IBM X-Force ID: 166629.
CVSS v3 Severity:
5.9 Medium
(CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
)
5.2 Medium
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
5.9 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
)
5.2 Medium
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
CVSS v2 Severity:
4.3 Medium
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Partial
5.4 Medium
(CCN CVSS v2 Vector:
AV:N/AC:H/Au:N/C:N/I:N/A:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
High
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Complete
Vulnerability Type:
CWE-20
Vulnerability Consequences:
Denial of Service
References:
Source: MITRE
Type: CNA
CVE-2019-4568
Source: XF
Type: UNKNOWN
ibm-mq-cve20194568-dos(166629)
Source: XF
Type: VDB Entry, Vendor Advisory
ibm-mq-cve20194568-dos (166629)
Source: CCN
Type: IBM Security Bulletin 1106517 (MQ)
IBM MQ and IBM MQ Appliance are vulnerable to a denial of service attack caused by an error within the clustering code. (CVE-2019-4568)
Source: CONFIRM
Type: Vendor Advisory
https://www.ibm.com/support/pages/node/1106517
Source: CCN
Type: IBM Security Bulletin 6208035 (Sterling B2B Integrator)
Multiple Security Vulnerabilities in IBM MQ Affect IBM Sterling B2B Integrator
Vulnerable Configuration:
Configuration 1
:
cpe:/a:ibm:mq:*:*:*:*:*:*:*:*
(Version >= 8.0.0.0 and < 8.0.0.14)
OR
cpe:/a:ibm:mq:*:*:*:*:lts:*:*:*
(Version >= 9.0.0.0 and < 9.0.0.8)
OR
cpe:/a:ibm:mq_appliance:*:*:*:*:*:*:*:*
(Version >= 8.0.0.0 and < 8.0.0.14)
AND
cpe:/o:hp:hp-ux:-:*:*:*:*:*:*:*
OR
cpe:/o:ibm:aix:-:*:*:*:*:*:*:*
OR
cpe:/o:linux:linux_kernel:-:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows:-:*:*:*:*:*:*:*
OR
cpe:/o:oracle:solaris:-:*:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:ibm:websphere_mq:9.0.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.1:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.2:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.8:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.9:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.3:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.0:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.10:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.0:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.4:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.5:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.11:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.6:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.12:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:9.0.0.7:*:*:*:*:*:*:*
OR
cpe:/a:ibm:websphere_mq:8.0.0.13:*:*:*:*:*:*:*
AND
cpe:/a:ibm:sterling_b2b_integrator:5.2.0.0:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
ibm
mq *
ibm
mq *
ibm
mq appliance *
hp
hp-ux -
ibm
aix -
linux
linux kernel -
microsoft
windows -
oracle
solaris -
ibm
websphere mq 9.0.0.1
ibm
websphere mq 8.0.0.1
ibm
websphere mq 8.0.0.2
ibm
websphere mq 8.0.0.3
ibm
websphere mq 8.0.0.4
ibm
websphere mq 8.0.0.5
ibm
websphere mq 8.0.0.6
ibm
websphere mq 8.0.0.7
ibm
websphere mq 9.0.0.2
ibm
websphere mq 8.0.0.8
ibm
websphere mq 8.0.0.9
ibm
websphere mq 9.0.0.3
ibm
websphere mq 8.0.0.0
ibm
websphere mq 8.0.0.10
ibm
websphere mq 9.0.0.0
ibm
websphere mq 9.0.0.4
ibm
websphere mq 9.0.0.5
ibm
websphere mq 8.0.0.11
ibm
websphere mq 9.0.0.6
ibm
websphere mq 8.0.0.12
ibm
websphere mq 9.0.0.7
ibm
websphere mq 8.0.0.13
ibm
sterling b2b integrator 5.2.0.0