CVE-2015-1958: High severity ibm websphere mq light vulnerability
Published Aug 3, 2015
·Updated
IBM MQ Light before 1.0.0.2 allows remote attackers to cause a denial of service (disk consumption) via a crafted byte sequence in authentication data, a different vulnerability than CVE-2015-1956 and CVE-2015-1987.
Affected Software
2 affected components
IBM WebSphere MQ Light=1.0
IBM WebSphere MQ Light=1.0.0.1
Event History
Aug 3, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1958?
The severity of CVE-2015-1958 is classified as a denial of service vulnerability.
2
How does CVE-2015-1958 affect IBM WebSphere MQ Light?
CVE-2015-1958 allows remote attackers to exploit a crafted byte sequence in authentication data causing disk consumption.
3
What versions of IBM WebSphere MQ Light are affected by CVE-2015-1958?
IBM WebSphere MQ Light versions before 1.0.0.2, including 1.0 and 1.0.0.1, are affected by CVE-2015-1958.
4
How do I fix CVE-2015-1958?
To fix CVE-2015-1958, upgrade IBM WebSphere MQ Light to version 1.0.0.2 or later.
5
Is there a workaround for CVE-2015-1958?
There are no known workarounds for CVE-2015-1958, so upgrading is recommended.