CVE-2017-1612: High severity ibm websphere mq appliance vulnerability
IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module could be used to execute untrusted code under 'mqm' user. IBM X-Force ID: 132953.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1612?
CVE-2017-1612 is a vulnerability in IBM WebSphere MQ 7.0, 7.1, 7.5, 8.0, and 9.0 service trace module that could be used to execute untrusted code under the 'mqm' user.
What is the severity of CVE-2017-1612?
The severity of CVE-2017-1612 is high (7.8).
Which versions of IBM WebSphere MQ are affected by CVE-2017-1612?
IBM WebSphere MQ versions 7.0, 7.1, 7.5, 8.0, and 9.0 are affected by CVE-2017-1612.
How can I fix CVE-2017-1612?
Upgrade to a fixed version of IBM WebSphere MQ (7.5.0.9, 8.0.0.8, or 9.0.4.0) or apply the appropriate fix according to the vendor's instructions.
Where can I find more information about CVE-2017-1612?
You can find more information about CVE-2017-1612 in the IBM Security Bulletin (http://www.ibm.com/support/docview.wss?uid=swg22009918), SecurityFocus (http://www.securityfocus.com/bid/102479), and SecurityTracker (http://www.securitytracker.com/id/1040175).