IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mq_operator | Ibm | 2.0.0 (including) | 2.0.24 (excluding) |
Mq_operator | Ibm | 2.2.0 (including) | 2.2.2 (including) |
Mq_operator | Ibm | 2.3.0 (including) | 2.3.3 (including) |
Mq_operator | Ibm | 2.4.0 (including) | 2.4.8 (including) |
Mq_operator | Ibm | 3.1.0 (including) | 3.1.3 (including) |
Mq_operator | Ibm | 3.2.0 (including) | 3.2.2 (excluding) |
Mq_operator | Ibm | 3.0.0 (including) | 3.0.0 (including) |
Mq_operator | Ibm | 3.0.1 (including) | 3.0.1 (including) |
This Pillar covers several possibilities: