CVE-2015-1985: Medium severity ibm mq appliance firmware vulnerability
Published Jan 3, 2016
·Updated
The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.
Affected Software
1 affected component
IBM MQ Appliance M2000<=8.0.0.3
Event History
Jan 3, 2016
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1985?
CVE-2015-1985 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive keys.
2
How do I fix CVE-2015-1985?
To fix CVE-2015-1985, upgrade the IBM MQ M2000 appliances to version 8.0.0.4 or later.
3
Who is affected by CVE-2015-1985?
CVE-2015-1985 affects local users of IBM MQ M2000 appliances running versions before 8.0.0.4.
4
What does CVE-2015-1985 allow an attacker to do?
CVE-2015-1985 allows attackers to bypass password requirements and access private keys on affected systems.
5
When was CVE-2015-1985 published?
CVE-2015-1985 was published in 2015 and addressed issues with IBM MQ M2000 appliances.