Overview
- Description
- IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 4.3
- Impact score
- 1.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 3.0
- Type
- Secondary
- Base score
- 3.1
- Impact score
- 1.4
- Exploitability score
- 1.6
- Vector string
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity
- LOW
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-209
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:mq_appliance:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "691172A5-00C2-42D2-A7C9-354EBF5B3408", "versionEndExcluding": "8.0.0.15", "versionStartIncluding": "8.0" }, { "criteria": "cpe:2.3:a:ibm:mq_appliance:*:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "52062DF3-A5E8-4218-B5CC-85981ED21FF9", "versionEndExcluding": "9.1.0.6", "versionStartIncluding": "9.1.0.0" }, { "criteria": "cpe:2.3:a:ibm:mq_appliance:*:*:*:*:continuous_delivery:*:*:*", "vulnerable": true, "matchCriteriaId": "46DAA494-9818-445A-93EE-A20BF8736F29", "versionEndExcluding": "9.2.0.0", "versionStartIncluding": "9.1.0.0" } ], "operator": "OR" } ] } ]