6.5

CVE-2019-4141

IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2 is vulnerable to a denial of service attack caused by a memory leak in the clustering code. IBM X-Force ID: 158337.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Mq SwEdition - Version >= 7.1.0.0 <= 7.1.0.9
Ibm ≫ Websphere Mq SwEdition - Version >= 7.5.0.0 <= 7.5.0.9
Ibm ≫ Websphere Mq SwEdition - Version >= 8.0.0.0 <= 8.0.0.11
Ibm ≫ Websphere Mq SwEdition lts Version >= 9.0.0.0 <= 9.0.0.6
Ibm ≫ Websphere Mq SwEdition - Version >= 9.1.0.0 <= 9.1.0.2
Ibm ≫ Websphere Mq SwEdition - Version >= 9.1.1 <= 9.1.2
Ibm ≫ Websphere Mq Appliance SwEdition - Version >= 8.0.0.0 <= 8.0.0.11
Ibm ≫ Websphere Mq Appliance SwEdition lts Version >= 9.1.0.0 <= 9.1.0.2
Ibm ≫ Websphere Mq Appliance SwEdition cd Version >= 9.1.1 <= 9.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.34% 0.675
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
IBM 5.3 1.6 3.6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://exchange.xforce.ibmcloud.com/vulnerabilities/158337
Vendor Advisory
VDB Entry
https://www.ibm.com/support/pages/node/876772
Patch
Vendor Advisory