CVE-2020-4682

Description

IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 186509.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.993

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-4055,CVE-2020-4682 are affected in IBM MQ 8.0.0.10Windows
Vulnerabilities CVE-2019-4227,CVE-2019-4378,CVE-2020-4682 are affected in IBM MQ 8.0.0.12Windows
Vulnerabilities CVE-2019-4261,CVE-2020-4682 are affected in IBM MQ 8.0.0.11Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0.0.13Windows
Vulnerabilities CVE-2020-4310,CVE-2020-4320,CVE-2020-4682 are affected in IBM MQ 8.0.0.14Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0.0.0Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.1Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.15Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.2Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.3Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.4Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.5Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.6Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.7Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.8Windows
Vulnerabilities CVE-2020-4682 are affected in IBM MQ 8.0.0.9Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.1.2.0Windows
Multiple Vulnerabilities are affected in IBM Sterling B2B Integrator 6.0.3.7Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0.0.5Windows
Multiple Vulnerabilities are affected in IBM MQ 8.0.0.6Windows
Vulnerabilities CVE-2017-1612,CVE-2020-4682 are affected in IBM MQ 8.0.0.7Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234