IBM Family (IBM i, IBM MQ) Security Update Recommendations
Overview
We have released updates to fix vulnerabilities in the IBM family of products. users of affected versions are advised to update to the latest version.
Affected Products
CVE-2024-25050
- IBM i versions 7.5, 7.4, 7.3, and 7.2
CVE-2024-25048
- IBM MQ Appliance 9.3 LTS versions
- IBM MQ Appliance 9.3 CD versions
Resolved Vulnerabilities
Privilege escalation vulnerability when using the IBM i networking and compiler infrastructure due to an unauthorized library call by a local user (CVE-2024-25050)
Heap-based buffer overflow vulnerability due to improper boundary checking in IBM MQ (CVE-2024-25048)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-25050
- update based on “Remediation/Fixes” on the referenced site[1]
CVE-2024-25048
- updated based on “Remediation/Fixes” in reference [2]
Referenced Sites
[1] Security Bulletin: IBM i is vulnerable to a local privilege escalation due to an unqualified library call in networking and compiler infrastructure [CVE-2024-25050]
https://www.ibm.com/support/pages/node/7149672
[2] Security Bulletin: IBM MQ Appliance is vulnerable to a buffer overflow (CVE-2024-25048)