CVE Vulnerabilities

CVE-2023-26284

Published: Mar 15, 2023 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.

Affected Software

Name Vendor Start Version End Version
Mq_certified_container Ibm 9.3.0.1 (including) 9.3.0.4 (excluding)
Mq_certified_container Ibm 9.3.1.0 (including) 9.3.2.0 (excluding)

References