First published: Mon Jul 23 2018(Updated: )
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | >=7.5.0.0<=7.5.0.8 | |
IBM WebSphere MQ | >=8.0.0.0<=8.0.0.9 | |
IBM WebSphere MQ | >=9.0.0.0<=9.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1503 is a vulnerability in IBM WebSphere MQ 7.5, 8.0, and 9.0 that allows a remotely authenticated attacker to send invalid or malformed headers, causing messages to not be transmitted on the affected channel.
CVE-2018-1503 has a severity value of 4.3, which is considered medium.
IBM WebSphere MQ versions 7.5.0.0 to 7.5.0.8, 8.0.0.0 to 8.0.0.9, and 9.0.0.0 to 9.0.0.3 are affected by CVE-2018-1503.
To fix CVE-2018-1503, apply the appropriate fix pack or interim fix provided by IBM for your version of IBM WebSphere MQ.
You can find more information about CVE-2018-1503 on the IBM support website and SecurityFocus.