CVE-2024-39742
HIGHDescription
IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
| ibm | mq_operator |
References
Frequently Asked Questions
What is CVE-2024-39742? +
How severe is CVE-2024-39742? +
What products are affected by CVE-2024-39742? +
How do I check if I'm vulnerable to CVE-2024-39742? +
Related Vulnerabilities
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions …
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, …
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) …
A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability …
A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this …
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of …