CVE-2015-2013: Medium severity ibm websphere mq appliance vulnerability
Published Sep 14, 2015
·Updated
IBM WebSphere MQ 7.0.1 before 7.0.1.13 allows remote attackers to cause a denial of service (channel-agent abend and process outage) via a crafted selection string in an MQI call.
Affected Software
13 affected components
IBM WebSphere MQ=7.0.1.0
IBM WebSphere MQ=7.0.1.1
IBM WebSphere MQ=7.0.1.2
IBM WebSphere MQ=7.0.1.3
IBM WebSphere MQ=7.0.1.4
IBM WebSphere MQ=7.0.1.5
IBM WebSphere MQ=7.0.1.6
IBM WebSphere MQ=7.0.1.7
IBM WebSphere MQ=7.0.1.8
IBM WebSphere MQ=7.0.1.9
IBM WebSphere MQ=7.0.1.10
IBM WebSphere MQ=7.0.1.11
IBM WebSphere MQ=7.0.1.12
Remediation
Patch Available
Event History
Sep 14, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2013?
CVE-2015-2013 has a severity rating that indicates it can cause a denial of service.
2
How do I fix CVE-2015-2013?
Fix CVE-2015-2013 by updating IBM WebSphere MQ to version 7.0.1.13 or later.
3
Which versions of IBM WebSphere MQ are affected by CVE-2015-2013?
CVE-2015-2013 affects IBM WebSphere MQ versions 7.0.1.0 through 7.0.1.12.
4
What is the impact of CVE-2015-2013?
The impact of CVE-2015-2013 is a denial of service resulting from unhandled crafted selection strings.
5
Who can exploit CVE-2015-2013?
CVE-2015-2013 can be exploited by remote attackers who send crafted MQI calls.