CVE-2017-1285: Input Validation
Published Jul 12, 2017
·Updated
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to remain in a running state but not process messages. IBM X-Force ID: 125146.
Affected Software
2 affected components
IBM WebSphere MQ=9.0.1
IBM WebSphere MQ=9.0.2
Remediation
Patch Available
Event History
Jul 12, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1285?
CVE-2017-1285 has a medium severity rating due to its potential impact on message processing in IBM WebSphere MQ.
2
How do I fix CVE-2017-1285?
To fix CVE-2017-1285, users should upgrade to a patched version of IBM WebSphere MQ beyond 9.0.2.
3
Who is affected by CVE-2017-1285?
CVE-2017-1285 affects authenticated users of IBM WebSphere MQ versions 9.0.1 and 9.0.2.
4
What systems are vulnerable to CVE-2017-1285?
Systems running IBM WebSphere MQ version 9.0.1 or 9.0.2 are vulnerable to CVE-2017-1285.
5
What type of attack can exploit CVE-2017-1285?
CVE-2017-1285 can be exploited by sending a specially crafted message that causes a channel to halt message processing.