CVE-2015-1955: High severity ibm websphere mq light vulnerability
Published Aug 3, 2015
·Updated
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a crafted byte sequence in authentication data.
Affected Software
2 affected components
IBM WebSphere MQ Light=1.0
IBM WebSphere MQ Light=1.0.0.1
Event History
Aug 3, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1955?
CVE-2015-1955 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2015-1955?
To fix CVE-2015-1955, upgrade IBM WebSphere MQ Light to version 1.0.0.2 or later.
3
What type of attack does CVE-2015-1955 facilitate?
CVE-2015-1955 allows remote attackers to perform a denial of service attack by consuming CPU resources.
4
Which versions of IBM WebSphere MQ Light are affected by CVE-2015-1955?
CVE-2015-1955 affects IBM WebSphere MQ Light versions 1.0 and 1.0.0.1.
5
Is authentication data relevant in CVE-2015-1955?
Yes, CVE-2015-1955 exploits vulnerabilities in crafted byte sequences within authentication data.