CVE-2016-0379: Low severity ibm websphere mq appliance vulnerability
Published Sep 26, 2016
·Updated
IBM WebSphere MQ 7.5 before 7.5.0.7 and 8.0 before 8.0.0.5 mishandles protocol flows, which allows remote authenticated users to cause a denial of service (channel outage) by leveraging queue-manager rights.
Affected Software
12 affected components
IBM WebSphere MQ=7.5
IBM WebSphere MQ=7.5.0.1
IBM WebSphere MQ=7.5.0.2
IBM WebSphere MQ=7.5.0.3
IBM WebSphere MQ=7.5.0.4
IBM WebSphere MQ=7.5.0.5
IBM WebSphere MQ=7.5.0.6
IBM WebSphere MQ=8.0
IBM WebSphere MQ=8.0.0.1
IBM WebSphere MQ=8.0.0.2
IBM WebSphere MQ=8.0.0.3
IBM WebSphere MQ=8.0.0.4
Remediation
Patch Available
Event History
Sep 26, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-0379?
CVE-2016-0379 is classified as a medium severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2016-0379?
To fix CVE-2016-0379, upgrade IBM WebSphere MQ to version 7.5.0.7 or 8.0.0.5 or later.
3
What systems are affected by CVE-2016-0379?
CVE-2016-0379 affects IBM WebSphere MQ versions 7.5 prior to 7.5.0.7 and 8.0 prior to 8.0.0.5.
4
What kind of attack does CVE-2016-0379 enable?
CVE-2016-0379 enables remote authenticated users to cause a denial of service through queue-manager rights.
5
Is there a patch available for CVE-2016-0379?
Yes, patches are included in the updated versions of IBM WebSphere MQ that mitigate the vulnerability.