CVE-2024-31919: IBM MQ denial of service
IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.
Other sources
IBM MQ, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31919?
CVE-2024-31919 is classified as a denial of service vulnerability.
How do I fix CVE-2024-31919?
To address CVE-2024-31919, upgrade your IBM MQ to a version that is not affected by this vulnerability.
What versions of IBM MQ are affected by CVE-2024-31919?
CVE-2024-31919 affects IBM MQ versions 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD under certain configurations.
Is there a workaround for CVE-2024-31919?
IBM has not publicly disclosed a specific workaround for CVE-2024-31919; the recommended action is to update the software.
What types of attacks are possible with CVE-2024-31919?
CVE-2024-31919 could allow attackers to cause a denial of service by exploiting issues in message processing when an API Exit is in use.