Vulnerability Name: | CVE-2020-4592 (CCN-184755) | ||||||||||||
Assigned: | 2019-12-30 | ||||||||||||
Published: | 2020-11-17 | ||||||||||||
Updated: | 2020-12-01 | ||||||||||||
Summary: | IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages. | ||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-4592 Source: XF Type: UNKNOWN ibm-mq-cve20204592-data-manipulation(184755) Source: XF Type: VDB Entry, Vendor Advisory ibm-mq-cve20204592-data-manipulation (184755) Source: CCN Type: IBM Security Bulletin 6359019 (MQ Appliance) IBM MQ Appliance is affected by a data corruption vulnerability (CVE-2020-4592) Source: CONFIRM Type: Patch, Vendor Advisory https://www.ibm.com/support/pages/node/6359019 Source: CCN Type: IBM Security Bulletin 6381404 (MQ for HPE NonStop) IBM MQ for HPE NonStop Server is affected by vulnerability CVE-2020-4592 Source: CCN Type: IBM Security Bulletin 6387806 (MQ) IBM MQ could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages. (CVE-2020-4592) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |