IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
The product performs a comparison that only examines a portion of a factor before determining whether there is a match, such as a substring, leading to resultant weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mq_operator | Ibm | 2.0.0 (including) | 2.0.24 (excluding) |
Mq_operator | Ibm | 2.2.0 (including) | 2.2.2 (including) |
Mq_operator | Ibm | 2.3.0 (including) | 2.3.3 (including) |
Mq_operator | Ibm | 2.4.0 (including) | 2.4.8 (including) |
Mq_operator | Ibm | 3.1.0 (including) | 3.1.3 (including) |
Mq_operator | Ibm | 3.2.0 (including) | 3.2.2 (excluding) |
Mq_operator | Ibm | 3.0.0 (including) | 3.0.0 (including) |
Mq_operator | Ibm | 3.0.1 (including) | 3.0.1 (including) |