CVE-2020-4338
IBM WebSphere MQ vulnerability analysis and mitigation

Overview

IBM MQ and IBM MQ Appliance version 9.1 CD contained a vulnerability (CVE-2020-4338) that could allow a local attacker to obtain sensitive information. This vulnerability was identified as an incomplete fix for a previous issue (CVE-2019-4719) and was disclosed on April 7, 2020. The vulnerability specifically affects the runmqras data functionality in IBM MQ systems (IBM Security).

Technical details

The vulnerability has a CVSS Base score of 5.1 with a vector of CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. This indicates a local attack vector with high attack complexity, no privileges required, no user interaction needed, and potential for high confidentiality impact. The technical issue involves the inclusion of sensitive data within runmqras data, which could potentially expose sensitive information to attackers (IBM Security).

Impact

The vulnerability could allow local attackers to obtain sensitive information through the exposure of sensitive data within runmqras data. The impact is primarily focused on confidentiality, with no direct impact on system integrity or availability (IBM Security).

Exploitability

The vulnerability requires local access to the system and has high attack complexity. While specific exploit details are not publicly available, the attack vector is limited to local access, which somewhat reduces the risk of widespread exploitation (IBM Security).

Mitigation and workarounds

IBM has released version 9.1.5 as a fix for affected systems running IBM MQ and IBM MQ Appliance V9.1 CD. As a workaround, users are advised to avoid using the -ftppassword parameter to runmqras. It's worth noting that other versions affected by the original CVE-2019-4719 issue are not affected by this specific vulnerability (IBM Security).

Additional resources


SourceThis report was generated using AI

Related IBM WebSphere MQ vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-36128HIGH7.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesOct 16, 2025
CVE-2025-36100MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesSep 07, 2025
CVE-2025-0985MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesFeb 28, 2025
CVE-2024-54175MEDIUM5.5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • mq
NoYesFeb 28, 2025
CVE-2026-1713MEDIUM5
  • IBM WebSphere MQ logoIBM WebSphere MQ
  • cpe:2.3:a:ibm:mq
NoYesMar 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management