First published: Wed Jul 12 2017(Updated: )
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | =9.0.1 | |
IBM WebSphere MQ Appliance | =9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1285 has a medium severity rating due to its potential impact on message processing in IBM WebSphere MQ.
To fix CVE-2017-1285, users should upgrade to a patched version of IBM WebSphere MQ beyond 9.0.2.
CVE-2017-1285 affects authenticated users of IBM WebSphere MQ versions 9.0.1 and 9.0.2.
Systems running IBM WebSphere MQ version 9.0.1 or 9.0.2 are vulnerable to CVE-2017-1285.
CVE-2017-1285 can be exploited by sending a specially crafted message that causes a channel to halt message processing.