CVE Vulnerabilities

CVE-2024-39743

Asymmetric Resource Consumption (Amplification)

Published: Jul 08, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 297172.

Weakness

The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary’s influence is “asymmetric.”

Affected Software

Name Vendor Start Version End Version
Mq_operator Ibm 2.0.0 (including) 2.0.24 (excluding)
Mq_operator Ibm 2.2.0 (including) 2.2.2 (including)
Mq_operator Ibm 2.3.0 (including) 2.3.3 (including)
Mq_operator Ibm 2.4.0 (including) 2.4.8 (including)
Mq_operator Ibm 3.1.0 (including) 3.1.3 (including)
Mq_operator Ibm 3.2.0 (including) 3.2.2 (excluding)
Mq_operator Ibm 3.0.0 (including) 3.0.0 (including)
Mq_operator Ibm 3.0.1 (including) 3.0.1 (including)

Potential Mitigations

References