CVE-2017-1557: Medium severity IBM WebSphere MQ vulnerability
Published Jan 2, 2018
·Updated
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.
Affected Software
13 affected components
IBM WebSphere MQ=8.0
IBM WebSphere MQ=8.0.0.1
IBM WebSphere MQ=8.0.0.2
IBM WebSphere MQ=8.0.0.3
IBM WebSphere MQ=8.0.0.4
IBM WebSphere MQ=8.0.0.5
IBM WebSphere MQ=8.0.0.6
IBM WebSphere MQ=8.0.0.7
IBM WebSphere MQ=9.0
IBM WebSphere MQ=9.0.0.1
IBM WebSphere MQ=9.0.1
IBM WebSphere MQ=9.0.2
IBM WebSphere MQ=9.0.3
Event History
Jan 2, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1557?
The severity of CVE-2017-1557 is medium with a severity value of 4.3.
2
How does CVE-2017-1557 affect IBM WebSphere MQ?
CVE-2017-1557 affects IBM WebSphere MQ versions 8.0 and 9.0.
3
What can an authenticated user with authority do to exploit CVE-2017-1557?
An authenticated user with authority can send a specially crafted request that could cause a channel process to cease processing further requests.
4
Is there a fix available for CVE-2017-1557?
Yes, IBM has released a fix for CVE-2017-1557. Please refer to the IBM support page for more information.
5
Where can I find more information about CVE-2017-1557?
You can find more information about CVE-2017-1557 on the IBM support page, the SecurityFocus website, and the IBM X-Force ID page.