IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison vulnerability. IBM X-Force ID: 297169.
| Software | From | Fixed in |
|---|---|---|
| ibm / mq_operator | 3.1.0 | 3.1.3.x |
| ibm / mq_operator | 2.4.0 | 2.4.8.x |
| ibm / mq_operator | 2.3.0 | 2.3.3.x |
| ibm / mq_operator | 2.2.0 | 2.2.2.x |
| ibm / mq_operator | 2.0.0 | 2.0.24 |
| ibm / mq_operator | 3.0.0 | 3.0.0.x |
| ibm / mq_operator | 3.0.1 | 3.0.1.x |
| ibm / mq_operator | 3.2.0 | 3.2.2 |