Vulnerability Name: | CVE-2023-28950 (CCN-251358) | ||||||||||||
Assigned: | 2023-05-10 | ||||||||||||
Published: | 2023-05-10 | ||||||||||||
Updated: | 2023-05-26 | ||||||||||||
Summary: | IBM MQ 8.0, 9.0, 9.1, 9.2, and 9.3 could disclose sensitive user information from a trace file if that functionality has been enabled. IBM X-Force ID: 251358. | ||||||||||||
CVSS v3 Severity: | 5.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 4.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:C/I:N/A:N)
| ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2023-28950 Source: XF Type: UNKNOWN ibm-mq-cve202328950-info-disc(251358) Source: CCN Type: IBM Security Bulletin 6985837 (MQ) IBM MQ trace can inadvertently trace sensitive data (CVE-2023-28950) Source: CCN Type: IBM Security Bulletin 7000017 (App Connect Enterprise Certified Container) IBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that use MQ Client nodes are vulnerable to disclosure of sensitive information due to [CVE-2023-28950] Source: CCN Type: IBM Security Bulletin 7011767 (App Connect Enterprise) IBM App Connect Enterprise and IBM Integration Bus are vulnerable to a denial of service due to IBM MQ (CVE-2023-26285, CVE-2023-28950) | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |