CVE-2015-4942: Medium severity ibm websphere mq light vulnerability
Published Jan 18, 2016
·Updated
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.
Affected Software
2 affected components
IBM WebSphere MQ Light=1.0
IBM WebSphere MQ Light=1.0.0.1
Event History
Jan 18, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4942?
CVE-2015-4942 has a severity level that allows for denial of service attacks on the IBM WebSphere MQ Light service.
2
How do I fix CVE-2015-4942?
To fix CVE-2015-4942, upgrade to IBM WebSphere MQ Light version 1.0.2 or later.
3
What type of attack is possible with CVE-2015-4942?
CVE-2015-4942 allows attackers to execute denial of service attacks by repeatedly connecting and disconnecting.
4
Which versions of IBM WebSphere MQ Light are affected by CVE-2015-4942?
CVE-2015-4942 affects IBM WebSphere MQ Light versions 1.0 and 1.0.0.1.
5
Can CVE-2015-4942 lead to a service crash?
Yes, CVE-2015-4942 can lead to a crash of the MQXR service due to the exploitation of this vulnerability.