Описание
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одновременно
Одно из
cpe:2.3:a:ibm:mq:9.1.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.2.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.3.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.3.0.0:*:*:*:lts:*:*:*
cpe:2.3:a:ibm:mq:9.4.0:*:*:*:continuous_delivery:*:*:*
cpe:2.3:a:ibm:mq:9.4.0.0:*:*:*:lts:*:*:*
Одно из
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*
EPSS
Процентиль: 35%
0.00143
Низкий
7.5 High
CVSS3
Дефекты
CWE-772
Связанные уязвимости
CVSS3: 7.5
github
4 месяца назад
IBM MQ 9.1, 9.2, 9.3, 9.4 LTS and 9.3, 9.4 CD is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service.
EPSS
Процентиль: 35%
0.00143
Низкий
7.5 High
CVSS3
Дефекты
CWE-772