CVE Vulnerabilities

CVE-2023-26284

Published: Mar 15, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.

Affected Software

NameVendorStart VersionEnd Version
Mq_certified_containerIbm9.3.0.1 (including)9.3.0.4 (excluding)
Mq_certified_containerIbm9.3.1.0 (including)9.3.2.0 (excluding)

References