CVE-2018-1503: Input Validation
IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow a remotely authenticated attacker to to send invalid or malformed headers that could cause messages to no longer be transmitted via the affected channel. IBM X-Force ID: 141339.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1503?
CVE-2018-1503 is a vulnerability in IBM WebSphere MQ 7.5, 8.0, and 9.0 that allows a remotely authenticated attacker to send invalid or malformed headers, causing messages to not be transmitted on the affected channel.
How severe is CVE-2018-1503?
CVE-2018-1503 has a severity value of 4.3, which is considered medium.
Which software versions are affected by CVE-2018-1503?
IBM WebSphere MQ versions 7.5.0.0 to 7.5.0.8, 8.0.0.0 to 8.0.0.9, and 9.0.0.0 to 9.0.0.3 are affected by CVE-2018-1503.
How can I fix CVE-2018-1503?
To fix CVE-2018-1503, apply the appropriate fix pack or interim fix provided by IBM for your version of IBM WebSphere MQ.
Where can I find more information about CVE-2018-1503?
You can find more information about CVE-2018-1503 on the IBM support website and SecurityFocus.