CVE-2014-6116: Medium severity ibm websphere mq appliance vulnerability
Published Oct 19, 2014
·Updated
The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.
Affected Software
1 affected component
IBM WebSphere MQ=8.0.0.1
Event History
Oct 19, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6116?
CVE-2014-6116 has a medium severity rating, indicating a moderate risk of exploitation.
2
How do I fix CVE-2014-6116?
To fix CVE-2014-6116, update to the latest version of IBM WebSphere MQ that addresses this vulnerability.
3
What type of vulnerability is CVE-2014-6116?
CVE-2014-6116 is an authentication bypass vulnerability affecting the Telemetry Component in WebSphere MQ.
4
Which versions of IBM WebSphere MQ are affected by CVE-2014-6116?
IBM WebSphere MQ version 8.0.0.1 is affected by CVE-2014-6116.
5
Can CVE-2014-6116 be exploited remotely?
Yes, CVE-2014-6116 can be exploited remotely by attackers who manipulate the JAASConfig property in an MQTT client configuration.