CVE Vulnerabilities

CVE-2020-4320

Improper Certificate Validation

Published: Jun 16, 2020 | Modified: Jun 23, 2020
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ Appliance and IBM MQ AMQP Channels 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD do not correctly block or allow clients based on the certificate distinguished name SSLPEER setting. IBM X-Force ID: 177403.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Mq Ibm 8.0.0.0 (including) 8.0.0.15 (excluding)
Mq Ibm 9.0.0.0 (including) 9.0.0.10 (excluding)
Mq Ibm 9.1.0 (including) 9.1.5 (excluding)
Mq Ibm 9.1.0.0 (including) 9.1.0.5 (excluding)

Potential Mitigations

References