Remote Code Execution Vulnerability in IBM WebSphere MQ Client
CVE-2018-1374

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 June 2018

Summary

A vulnerability in IBM WebSphere MQ allows for a remote code execution (RCE) attack when a client connects to a Queue Manager, potentially causing a segmentation fault in the Channel process (amqrmppa). This impacts multiple maintenance levels of the software, exposing systems to risks if left unaddressed.

Affected Version(s)

WebSphere MQ 7.1

WebSphere MQ 7.5

WebSphere MQ 7.5.0.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.