CVE-2023-28513

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:mq:9.0.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.2.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.2.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:lts:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:mq_appliance:9.2.0.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.3.0.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.3.0.0:*:*:*:lts:*:*:*

History

31 Jul 2023, 18:52

Type Values Removed Values Added
First Time Oracle solaris
Ibm aix
Hp
Ibm mq
Linux
Microsoft
Oracle
Ibm linux On Ibm Z
Ibm mq Appliance
Linux linux Kernel
Ibm
Ibm i
Hp hp-ux
Microsoft windows
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://www.ibm.com/support/pages/node/7007421 - (MISC) https://www.ibm.com/support/pages/node/7007421 - Patch, Vendor Advisory
References (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/250397 - (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/250397 - VDB Entry, Vendor Advisory
References (MISC) https://www.ibm.com/support/pages/node/7007731 - (MISC) https://www.ibm.com/support/pages/node/7007731 - Patch, Vendor Advisory
CPE cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.3.0.0:*:*:*:lts:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.2.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.3.0.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.0.0.0:*:*:*:lts:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq_appliance:9.2.0.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:mq:9.2.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*

19 Jul 2023, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-19 02:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-28513

Mitre link : CVE-2023-28513

CVE.ORG link : CVE-2023-28513


JSON object : View

Products Affected

ibm

  • mq
  • i
  • aix
  • linux_on_ibm_z
  • mq_appliance

linux

  • linux_kernel

oracle

  • solaris

hp

  • hp-ux

microsoft

  • windows
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation