IBM Security Bulletin: IBM MQ clients are vulnerable to a denial of service attack caused by consuming specifically crafted messages (CVE-2019-4261)
An error was found with the IBM MQ client message handling logic that causes a denial of service attack when specifically crafted messages are consumed.
CVE(s): CVE-2019-4261
Affected product(s) and affected version(s):
IBM WebSphere MQ V7.1 versions 7.1.0.0 – 7.1.0.9 IBM WepSphere MQ V7.5 versions 7.5.0.0 – 7.5.0.9
IBM MQ V8 versions 8.0.0.0 – 8.0.0.11 IBM MQ V9.0LTS versions 9.0.0.0 – 9.0.0.6
IBM MQ V9.1 LTS versions 9.1.0.0 – 9.1.0.2 IBM MQ V9.1 CD versions 9.1.0 – 9.1.2
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10886887
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/160013
The post IBM Security Bulletin: IBM MQ clients are vulnerable to a denial of service attack caused by consuming specifically crafted messages (CVE-2019-4261) appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team https://ift.tt/31c1lYE