SB2023030652 - Improper authorization in IBM Supplied MQ Advanced Queue Manager Container images



SB2023030652 - Improper authorization in IBM Supplied MQ Advanced Queue Manager Container images

Published: March 6, 2023

Security Bulletin ID SB2023030652
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authorization (CVE-ID: CVE-2023-26284)

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to improper authorization. All users authenticated with the cluster are granted administration access to the MQ Console, without checking IAM access rights.


Remediation

Install update from vendor's website.