First published: Wed Nov 07 2018(Updated: )
IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of service attack. IBM X-Force ID: 145456.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | >=8.0.0.0<=8.0.0.10 | |
IBM WebSphere MQ | >=9.0.0.0<=9.0.0.5 | |
IBM WebSphere MQ | >=9.0.1<=9.0.5 | |
IBM WebSphere MQ | =9.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1684.
The severity of CVE-2018-1684 is medium, with a severity value of 6.5.
IBM WebSphere MQ versions 8.0.0.0 to 8.0.0.10, 9.0.0.0 to 9.0.0.5, 9.0.1 to 9.0.5, and 9.1.0.0 are affected by CVE-2018-1684.
The vulnerability in IBM WebSphere MQ is an error with MQTT topic string publishing that can cause a denial of service attack.
To fix CVE-2018-1684, apply the necessary security patches provided by IBM and upgrade to a non-vulnerable version of IBM WebSphere MQ.