Severity
High
Analysis Summary
CVE-2024-39742 CVSS:8.1
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability.
CVE-2024-39743 CVSS:5.9
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to cause a denial of service under certain configurations due to a partial string comparison vulnerability.
Impact
- Denial of Service
- Gain Access
Indicators of Compromise
CVE
- CVE-2024-39742
- CVE-2024-39743
Affected Vendors
IBM
Affected Products
- IBM MQ Operator 2.3.0
- IBM MQ Operator 2.3.3
- IBM MQ Operator 2.0.0
- IBM MQ Operator 2.4.0
- IBM MQ Operator 2.2.0
- IBM MQ Operator 2.2.2
- IBM MQ Operator 3.0.0
- IBM MQ Operator 3.0.1
- IBM MQ Operator 3.1.0
- IBM MQ Operator 2.4.8
- IBM MQ Operator 3.1.3
- IBM MQ Operator 2.0.23
- IBM MQ Operator 3.2.0
- IBM MQ Operator 3.2.1
Remediation
Refer to IBM Security Advisory for patch, upgrade or suggested workaround information.

