Jun 11, 2019 9:01 am EDT
Categorized: Medium Severity
Share this post:
An issue was found within the IBM MQ Advanced Cloud Pak that would cause plain text passwords to be printed in the container logs. If these logs were mirrored to an external logging service, such as the logging service in IBM Cloud Private, then they would be visible there.
CVE(s): CVE-2019-4239
Affected product(s) and affected version(s):
IBM MQ Advanced Cloud Pak (IBM Cloud Private)
v1.0.0 – v3.0.1
IBM MQ Advanced Cloud Pak (IBM Cloud Private on RedHat OpenShift)
v2.1.0 – v2.3.1
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10886591
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/159465
from IBM Product Security Incident Response Team https://ibm.co/2X4yW8u
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.