CVE-2017-1760: High severity ibm websphere mq appliance vulnerability
Published Dec 11, 2017
·Updated
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a local user to crash the queue manager agent thread and expose some sensitive information. IBM X-Force ID: 126454.
Affected Software
21 affected components
IBM WebSphere MQ=7.5
IBM WebSphere MQ=7.5.0.1
IBM WebSphere MQ=7.5.0.2
IBM WebSphere MQ=7.5.0.3
IBM WebSphere MQ=7.5.0.4
IBM WebSphere MQ=7.5.0.5
IBM WebSphere MQ=7.5.0.6
IBM WebSphere MQ=7.5.0.7
IBM WebSphere MQ=7.5.0.8
IBM WebSphere MQ=8.0
IBM WebSphere MQ=8.0.0.1
IBM WebSphere MQ=8.0.0.2
IBM WebSphere MQ=8.0.0.3
IBM WebSphere MQ=8.0.0.4
IBM WebSphere MQ=8.0.0.5
IBM WebSphere MQ=8.0.0.6
IBM WebSphere MQ=9.0
IBM WebSphere MQ=9.0.0.1
IBM WebSphere MQ=9.0.1
IBM WebSphere MQ=9.0.2
IBM WebSphere MQ=9.0.3
Event History
Dec 6, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2017-1760?
CVE-2017-1760 is a vulnerability in IBM WebSphere MQ versions 7.5, 8.0, and 9.0 that could allow a local user to crash the queue manager agent thread and expose sensitive information.
2
How severe is CVE-2017-1760?
CVE-2017-1760 has a severity score of 7.1, which is considered high.
3
What is the affected software of CVE-2017-1760?
The affected software includes IBM WebSphere MQ versions 7.5, 8.0, and 9.0.
4
How can CVE-2017-1760 be exploited?
CVE-2017-1760 can be exploited by a local user to crash the queue manager agent thread and potentially expose sensitive information.
5
Is there a fix available for CVE-2017-1760?
Yes, IBM has provided a fix for CVE-2017-1760. Please refer to the official IBM support document for more information.