Security Bulletin
Summary
A Remote Code Execution issue was identified within the Log4j fix for CVE-2021-44228 that is used by Fabric Gateway to provide logging functionality. Fabric Gateway is used by the IBM MQ blockchain bridge component of IBM MQ to provide connection capability between IBM MQ queue managers and Hyperledger Fabric. The IBM MQ Blockchain Bridge is shipped as part of IBM MQ on Linux x86-64 only, under the MQSeriesBCBridge RPM package. Based on current knowledge and analysis, no other IBM MQ components or installable packages are affected. This bulletin provides patch information to address the reported both Log4j vulnerabilities (CVE-2021-45046)
Vulnerability Details
DESCRIPTION: Apache Log4j is vulnerable to a denial of service, caused by an incomplete fix of CVE-2021-44228 in certain non-default configurations. A remote attacker with control over Thread Context Map (MDC) input data or a Thread Context Map pattern to exploit this vulnerability to craft malicious input data using a JNDI Lookup pattern and cause a denial of service.
CVSS Base score: 3.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/215195 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Affected Products and Versions
Affected Product(s) | Version(s) |
IBM MQ | 9.2 CD |
IBM MQ | 9.1 CD |
IBM MQ | 9.2 LTS |
Remediation/Fixes
This issue is resolved by APAR IT39444
The following patches resolve CVE-2021-45046 & CVE-2021-44228.
IBM MQ version 9.2 LTS
Apply iFix 9.2.0.4-IBM-MQ-LinuxX64-LAIT39386-IT39444
IBM MQ version 9.1 CD and 9.2 CD
Workarounds and Mitigations
The IBM MQ Blockchain Bridge is shipped as part of IBM MQ on Linux x86-64 only, under the MQSeriesBCBridge RPM package. Based on current knowledge and analysis, no other IBM MQ components or installable packages are affected.
Get Notified about Future Security Bulletins
References
Acknowledgement
Change History
17 Dec 2021: Initial Publication
17 Dec 2021: Corrected APAR number and added details of patch fixing both Log4J CVEs
20 Dec 2021: Corrected Applicability to include IBM MQ Base
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Document Location
Worldwide
Was this topic helpful?
Document Information
Modified date:
20 December 2021
UID
ibm16527924