CVE-2017-1337: High severity ibm websphere mq appliance vulnerability
Published Jul 10, 2017
·Updated
IBM WebSphere MQ 9.0.1 and 9.0.2 Java/JMS application can incorrectly transmit user credentials in plain text. IBM X-Force ID: 126245.
Affected Software
2 affected components
IBM WebSphere MQ=9.0.1
IBM WebSphere MQ=9.0.2
Event History
Jul 10, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1337?
CVE-2017-1337 is classified as a high severity vulnerability due to the risk of transmitting user credentials in plain text.
2
How do I mitigate CVE-2017-1337?
Mitigation for CVE-2017-1337 involves upgrading to IBM WebSphere MQ version 9.0.3 or later where the issue is resolved.
3
What versions of IBM WebSphere MQ are affected by CVE-2017-1337?
IBM WebSphere MQ versions 9.0.1 and 9.0.2 are affected by CVE-2017-1337.
4
What impact does CVE-2017-1337 have on user credentials?
CVE-2017-1337 allows user credentials to be transmitted without encryption, making them vulnerable to interception.
5
Is there a workaround for CVE-2017-1337 if I cannot upgrade?
If immediate upgrading is not possible, users should implement additional network security measures such as VPNs to encrypt communications.