First published: Mon Jan 18 2016(Updated: )
IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Light | =1.0 | |
IBM WebSphere MQ Light | =1.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4942 has a severity level that allows for denial of service attacks on the IBM WebSphere MQ Light service.
To fix CVE-2015-4942, upgrade to IBM WebSphere MQ Light version 1.0.2 or later.
CVE-2015-4942 allows attackers to execute denial of service attacks by repeatedly connecting and disconnecting.
CVE-2015-4942 affects IBM WebSphere MQ Light versions 1.0 and 1.0.0.1.
Yes, CVE-2015-4942 can lead to a crash of the MQXR service due to the exploitation of this vulnerability.