Tuesday, June 11, 2019

IBM Security Bulletin: IBM MQ Advanced Cloud Pak may print out plain text credentials in logs. (CVE-2019-4239)

Jun 11, 2019 9:01 am EDT

Categorized: Medium Severity

Share this post:

An issue was found within the IBM MQ Advanced Cloud Pak that would cause plain text passwords to be printed in the container logs. If these logs were mirrored to an external logging service, such as the logging service in IBM Cloud Private, then they would be visible there.

CVE(s): CVE-2019-4239

Affected product(s) and affected version(s):

IBM MQ Advanced Cloud Pak (IBM Cloud Private)

v1.0.0 – v3.0.1

IBM MQ Advanced Cloud Pak (IBM Cloud Private on RedHat OpenShift)

v2.1.0 – v2.3.1

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: https://www-01.ibm.com/support/docview.wss?uid=ibm10886591
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/159465



from IBM Product Security Incident Response Team https://ibm.co/2X4yW8u

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.