Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-4319


IBM MQ, IBM MQ Appliance, and IBM MQ for HPE NonStop 8.0, 9.1 LTS, and 9.1 CD could allow under special circumstances, an authenticated user to obtain sensitive information due to a data leak from an error message within the pre-v7 pubsub logic. IBM X-Force ID: 177402.


Published

2020-07-28T12:15:12.270

Last Modified

2024-11-21T05:32:35.023

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm mq_appliance < 8.0.0.15 Yes
Application ibm mq_appliance < 9.1.0.6 Yes
Application ibm mq_appliance < 9.2.0.0 Yes

References