CVE-2015-0118: Medium severity ibm websphere message broker vulnerability
IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection to an Integration Bus node.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the weak TLS cipher issue in IBM WebSphere Message Broker?
The vulnerability ID for the weak TLS cipher issue in IBM WebSphere Message Broker is CVE-2015-0118.
What versions of IBM WebSphere Message Broker are affected by CVE-2015-0118?
CVE-2015-0118 affects IBM WebSphere Message Broker versions 7.0 before 7007 IF2, 8.0 before 8005 IF1, and Integration Toolkit 9.0 before 9003 IF1.
What types of attacks does CVE-2015-0118 enable?
CVE-2015-0118 may allow remote attackers to obtain sensitive information by sniffing the network due to weak TLS ciphers.
How do I mitigate CVE-2015-0118?
To mitigate CVE-2015-0118, upgrade to the fixed versions: IBM WebSphere Message Broker 7.0.0.7 or later, 8.0.0.5 or later, and Integration Toolkit 9.0.0.3 or later.
Is CVE-2015-0118 related to specific IBM products?
Yes, CVE-2015-0118 is related to IBM WebSphere Message Broker and IBM Integration Bus.