CVE-2018-1374: Input Validation
An IBM WebSphere MQ (Maintenance levels 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4) client connecting to a Queue Manager could cause a SIGSEGV in the Channel process amqrmppa. IBM X-Force ID: 137775.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1374?
The severity of CVE-2018-1374 is medium with a severity value of 6.5.
Which IBM WebSphere MQ versions are affected by CVE-2018-1374?
IBM WebSphere MQ versions 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.8, 8.0.0.0 - 8.0.0.8, 9.0.0.0 - 9.0.0.2, and 9.0.0 - 9.0.4 are affected by CVE-2018-1374.
How can CVE-2018-1374 be exploited?
An attacker can exploit CVE-2018-1374 by having an IBM WebSphere MQ client connect to a Queue Manager, which could cause a SIGSEGV in the Channel process amqrmppa.
What is the IBM X-Force ID for CVE-2018-1374?
The IBM X-Force ID for CVE-2018-1374 is 137775.
Is there a fix available for CVE-2018-1374?
Yes, IBM has released fixes for CVE-2018-1374. Please refer to the provided references for more information.