7.5
CVE-2023-28513
- EPSS 0.97%
- Veröffentlicht 19.07.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 07:55:15
- Erkennungen
IBM MQ denial of service
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Mq Appliance Version 9.2.0.0 SwEdition continuous_delivery
Ibm ≫ Mq Appliance Version 9.2.0.0 SwEdition lts
Ibm ≫ Mq Appliance Version 9.3.0.0 SwEdition continuous_delivery
Ibm ≫ Mq Appliance Version 9.3.0.0 SwEdition lts
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.97% | 0.58 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| IBM | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://exchange.xforce.ibmcloud.com/vulnerabilities/250397
https://www.ibm.com/support/pages/node/7007421
https://www.ibm.com/support/pages/node/7007731