First published: Mon Jul 10 2017(Updated: )
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | =9.0.1 | |
IBM WebSphere MQ Appliance | =9.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1337 is classified as a high severity vulnerability due to the risk of transmitting user credentials in plain text.
Mitigation for CVE-2017-1337 involves upgrading to IBM WebSphere MQ version 9.0.3 or later where the issue is resolved.
IBM WebSphere MQ versions 9.0.1 and 9.0.2 are affected by CVE-2017-1337.
CVE-2017-1337 allows user credentials to be transmitted without encryption, making them vulnerable to interception.
If immediate upgrading is not possible, users should implement additional network security measures such as VPNs to encrypt communications.