ID

VAR-202011-1431


CVE

CVE-2020-4592


TITLE

IBM MQ Appliance  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-013740

DESCRIPTION

IBM MQ Appliance 9.1.CD and LTS could allow an authenticated user, under nondefault configuration to cause a data corruption attack due to an error when using segmented messages. IBM MQ Appliance Contains an unspecified vulnerability.Information may be tampered with

Trust: 1.62

sources: NVD: CVE-2020-4592 // JVNDB: JVNDB-2020-013740

AFFECTED PRODUCTS

vendor:ibmmodel:mq appliancescope:eqversion:9.1.0.0

Trust: 1.0

vendor:ibmmodel:mq appliancescope:eqversion:9.1 lts

Trust: 0.8

vendor:ibmmodel:mq appliancescope:eqversion: -

Trust: 0.8

vendor:ibmmodel:mq appliancescope:eqversion:9.1 cd

Trust: 0.8

sources: JVNDB: JVNDB-2020-013740 // NVD: CVE-2020-4592

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2020-4592
value: MEDIUM

Trust: 1.8

CNNVD: CNNVD-202011-1519
value: MEDIUM

Trust: 0.6

NVD: CVE-2020-4592
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2020-4592
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-4592
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-013740 // CNNVD: CNNVD-202011-1519 // NVD: CVE-2020-4592

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-013740 // NVD: CVE-2020-4592

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202011-1519

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202011-1519

CONFIGURATIONS

sources: NVD: CVE-2020-4592

PATCH

title:6359019 IBM X-Force Exchangeurl:https://www.ibm.com/support/pages/node/6359019

Trust: 0.8

title:IBM MQ Appliance Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqbyid.tag?id=134749

Trust: 0.6

sources: JVNDB: JVNDB-2020-013740 // CNNVD: CNNVD-202011-1519

EXTERNAL IDS

db:NVDid:CVE-2020-4592

Trust: 2.4

db:JVNDBid:JVNDB-2020-013740

Trust: 0.8

db:CNNVDid:CNNVD-202011-1519

Trust: 0.6

sources: JVNDB: JVNDB-2020-013740 // CNNVD: CNNVD-202011-1519 // NVD: CVE-2020-4592

REFERENCES

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/184755

Trust: 1.6

url:https://www.ibm.com/support/pages/node/6359019

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-4592

Trust: 1.4

url:https://vigilance.fr/vulnerability/ibm-mq-denial-of-service-via-data-corruption-33908

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-could-allow-an-authenticated-user-under-nondefault-configuration-to-cause-a-data-corruption-attack-due-to-an-error-when-using-segmented-messages-cve-2020-4592/

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-mq-for-hpe-nonstop-server-is-affected-by-vulnerability-cve-2020-4592/

Trust: 0.6

sources: JVNDB: JVNDB-2020-013740 // CNNVD: CNNVD-202011-1519 // NVD: CVE-2020-4592

SOURCES

db:JVNDBid:JVNDB-2020-013740
db:CNNVDid:CNNVD-202011-1519
db:NVDid:CVE-2020-4592

LAST UPDATE DATE

2022-05-04T10:03:20.574000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-013740date:2021-07-13T07:51:00
db:CNNVDid:CNNVD-202011-1519date:2020-12-21T00:00:00
db:NVDid:CVE-2020-4592date:2020-12-01T19:02:00

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-013740date:2021-07-13T00:00:00
db:CNNVDid:CNNVD-202011-1519date:2020-11-17T00:00:00
db:NVDid:CVE-2020-4592date:2020-11-18T18:15:00