First published: Wed Aug 29 2012(Updated: )
IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3295 is considered a high severity vulnerability due to the potential for remote attackers to gain unauthorized access.
To fix CVE-2012-3295, upgrade to a later version of IBM WebSphere MQ that addresses this vulnerability.
CVE-2012-3295 allows attackers to bypass security configuration, potentially leading to unauthorized access to the queue manager.
Check if your system is running IBM WebSphere MQ version 7.1 and review the security configuration for SVRCONN channels.
Organizations using IBM WebSphere MQ 7.1 with improperly configured SVRCONN channels are primarily affected by CVE-2012-3295.