CVE-2023-26284
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/03/2023
Last modified:
07/11/2023
Description
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:lts:*:*:* | 9.3.0.1 (including) | 9.3.0.4 (excluding) |
| cpe:2.3:a:ibm:mq_certified_container:*:*:*:*:continous_delivery:*:*:* | 9.3.1.0 (including) | 9.3.2.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



