CVE-2015-0173
Published Jun 28, 2015
Last updated 7 years ago
Overview
- Description
- The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier for remote attackers to bypass intended restrictions on MQ message data by predicting an ID value.
- Source
- psirt@us.ibm.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-17
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ibm:websphere_mq_internet_pass_thru:*:*:*:*:*:websphere_mq:*:*", "vulnerable": true, "matchCriteriaId": "E1851C33-7027-4C86-A791-654FF06E359E", "versionEndIncluding": "2.1.0.1" } ], "operator": "OR" } ] } ]