CVE-2015-1956: High severity ibm websphere mq light vulnerability
Published Aug 3, 2015
·Updated
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1958 and CVE-2015-1987.
Affected Software
2 affected components
IBM WebSphere MQ Light=1.0
IBM WebSphere MQ Light=1.0.0.1
Event History
Aug 3, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1956?
CVE-2015-1956 is classified as a denial of service vulnerability due to disk consumption issues.
2
How do I fix CVE-2015-1956?
To mitigate CVE-2015-1956, upgrade IBM WebSphere MQ Light to version 1.0.0.2 or later.
3
What software is affected by CVE-2015-1956?
CVE-2015-1956 affects IBM WebSphere MQ Light versions 1.0 and 1.0.0.1.
4
Can CVE-2015-1956 be exploited remotely?
Yes, CVE-2015-1956 can be exploited remotely by sending a crafted byte sequence in the authentication data.
5
Are there any known exploits for CVE-2015-1956?
There are no public exploits specifically known for CVE-2015-1956 at this time.