CVE-2023-26284

HIGH

IBM MQ Certified Container <9.3.0.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/6960201

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 66.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (2)
ibm/mq_certified_container 9.3.0.1 - 9.3.0.4
ibm/mq_certified_container 9.3.1.0 - 9.3.2.0
Published Mar 15, 2023
Tracked Since Feb 18, 2026