CVE-2014-4771: Low severity ibm websphere mq appliance vulnerability
IBM WebSphere MQ 7.0.1 before 7.0.1.13, 7.1 before 7.1.0.6, 7.5 before 7.5.0.5, and 8 before 8.0.0.1 allows remote authenticated users to cause a denial of service (queue-slot exhaustion) by leveraging PCF query privileges for a crafted query.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4771?
CVE-2014-4771 has been classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2014-4771?
To fix CVE-2014-4771, upgrade IBM WebSphere MQ to versions 7.0.1.13, 7.1.0.6, 7.5.0.5, or 8.0.0.1 or later.
Who is affected by CVE-2014-4771?
CVE-2014-4771 affects IBM WebSphere MQ versions 7.0.1, 7.1, 7.5, and 8.0 prior to their respective fixed versions.
What type of attack is possible due to CVE-2014-4771?
CVE-2014-4771 allows authenticated remote users to conduct a denial of service attack by exhausting queue slots.
Is CVE-2014-4771 exploitable without authentication?
No, CVE-2014-4771 requires remote authenticated access to exploit the vulnerability.