CVE-2011-1224: Medium severity ibm websphere mq vulnerability
Published Jul 7, 2011
·Updated
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
Affected Software
22 affected components
IBM WebSphere MQ=6.0
IBM WebSphere MQ=6.0.1.0
IBM WebSphere MQ=6.0.1.1
IBM WebSphere MQ=6.0.2.0
IBM WebSphere MQ=6.0.2.1
IBM WebSphere MQ=6.0.2.2
IBM WebSphere MQ=6.0.2.3
IBM WebSphere MQ=6.0.2.4
IBM WebSphere MQ=6.0.2.5
IBM WebSphere MQ=6.0.2.6
IBM WebSphere MQ=6.0.2.7
IBM WebSphere MQ=6.0.2.8
IBM WebSphere MQ=6.0.2.9
IBM WebSphere MQ=6.0.2.10
IBM WebSphere MQ=7.0
IBM WebSphere MQ=7.0.0.1
IBM WebSphere MQ=7.0.0.2
IBM WebSphere MQ=7.0.1.0
IBM WebSphere MQ=7.0.1.1
IBM WebSphere MQ=7.0.1.2
IBM WebSphere MQ=7.0.1.3
IBM WebSphere MQ=7.0.1.4
Event History
Jul 7, 2011
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1224?
CVE-2011-1224 is rated as a medium-severity vulnerability due to potential man-in-the-middle attack risks.
2
How do I fix CVE-2011-1224?
To remediate CVE-2011-1224, upgrade to IBM WebSphere MQ versions 6.0.2.11 or 7.0.1.5 or later.
3
What systems are affected by CVE-2011-1224?
CVE-2011-1224 affects IBM WebSphere MQ versions prior to 6.0.2.11 and 7.0.1.5.
4
What kind of attacks does CVE-2011-1224 enable?
CVE-2011-1224 allows attackers to spoof an SSL partner using a revoked certificate.
5
Is there a workaround for CVE-2011-1224?
No specific workaround exists for CVE-2011-1224; upgrading to the patched versions is recommended.