CVE Published: 15/03/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: ibm |
Vendor: IBM |
Product: MQ Certified Container Status : PUBLISHED
CVE-2023-26284 Description
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H