CVE-2015-1967: Infoleak
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1967?
CVE-2015-1967 is classified as a moderate severity vulnerability due to the risk of sensitive information disclosure.
How do I fix CVE-2015-1967?
To fix CVE-2015-1967, upgrade IBM WebSphere MQ to version 8.0.0.3 or later, which addresses the compatibility-mode option.
What type of attack does CVE-2015-1967 involve?
CVE-2015-1967 involves a remote attack that allows information disclosure by sniffing unprotected network sessions.
Which versions of IBM WebSphere MQ are affected by CVE-2015-1967?
CVE-2015-1967 affects IBM WebSphere MQ versions prior to 8.0.0.3, specifically version 8.0.0.2.
Is TLS support relevant to CVE-2015-1967?
Yes, the absence of TLS support in sessions makes CVE-2015-1967 a vulnerability due to potential data exposure.