- Description
- IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6ABA6343-CBEA-423B-A067-7A0EFB0E3FF9",
"versionEndExcluding": "9.3.0.4",
"versionStartIncluding": "9.3.0.1"
},
{
"criteria": "cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:continous_delivery:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9D1571A-EA86-4B53-8CEA-8DBEA2834EDE",
"versionEndExcluding": "9.3.2.0",
"versionStartIncluding": "9.3.1.0"
}
],
"operator": "OR"
}
]
}
]