SB2023030652 - Improper authorization in IBM Supplied MQ Advanced Queue Manager Container images
Published: March 6, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2023-26284)
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to improper authorization. All users authenticated with the cluster are granted administration access to the MQ Console, without checking IAM access rights.
Remediation
Install update from vendor's website.