CVE-2023-26284
Published Mar 15, 2023
Last updated a year ago
Overview
- Description
- IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "6ABA6343-CBEA-423B-A067-7A0EFB0E3FF9", "versionEndExcluding": "9.3.0.4", "versionStartIncluding": "9.3.0.1" }, { "criteria": "cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:continous_delivery:*:*:*", "vulnerable": true, "matchCriteriaId": "B9D1571A-EA86-4B53-8CEA-8DBEA2834EDE", "versionEndExcluding": "9.3.2.0", "versionStartIncluding": "9.3.1.0" } ], "operator": "OR" } ] } ]