CVE-2019-4378

Description

IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 command server is vulnerable to a denial of service attack caused by an authenticated and authorized user using specially crafted PCF messages. IBM X-Force ID: 162084.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.103

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-4227,CVE-2019-4378,CVE-2020-4682 are affected in IBM MQ 8.0.0.12Windows
Vulnerabilities CVE-2019-4378 are affected in IBM MQ 7.1.0.9Windows
Vulnerabilities CVE-2019-4378 are affected in IBM MQ 7.5.0.9Windows
Vulnerabilities CVE-2019-4378 are affected in IBM MQ 9.1.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.7Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234