First published: Fri Nov 12 2010(Updated: )
IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | =7.0.0.1 | |
IBM WebSphere MQ | =6.0.1.0 | |
IBM WebSphere MQ | =6.0 | |
IBM WebSphere MQ | =6.0.2.4 | |
IBM WebSphere MQ | =6.0.1.1 | |
IBM WebSphere MQ | =6.0.2.7 | |
IBM WebSphere MQ | =7.0.0.2 | |
IBM WebSphere MQ | =6.0.0.0 | |
IBM WebSphere MQ | =6.0.2.3 | |
IBM WebSphere MQ | =6.0.2.1 | |
IBM WebSphere MQ | =6.0.2.8 | |
IBM WebSphere MQ | =6.0.2.2 | |
IBM WebSphere MQ | =6.0.2.0 | |
IBM WebSphere MQ | =6.0.2.10 | |
IBM WebSphere MQ | =6.0.2.5 | |
IBM WebSphere MQ | =6.0.2.6 | |
IBM WebSphere MQ | =7.0 | |
IBM WebSphere MQ | =7.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2637 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2010-2637, upgrade to IBM WebSphere MQ version 6.0.2.9 or 7.0.1.1 or later.
CVE-2010-2637 affects IBM WebSphere MQ versions 6.0 prior to 6.0.2.9 and 7.0 prior to 7.0.1.1.
Yes, attackers can exploit CVE-2010-2637 by sniffing unencrypted network traffic to obtain sensitive credentials.
CVE-2010-2637 exposes usernames and passwords transmitted in the security parameters field of IBM WebSphere MQ.