CVE-2018-1684: Medium severity IBM WebSphere MQ vulnerability
Published Nov 9, 2018
·Updated
IBM WebSphere MQ 8.0 through 9.1 is vulnerable to a error with MQTT topic string publishing that can cause a denial of service attack. IBM X-Force ID: 145456.
Affected Software
4 affected components
IBM WebSphere MQ>=8.0.0.0<=8.0.0.10
IBM WebSphere MQ>=9.0.0.0<=9.0.0.5
IBM WebSphere MQ>=9.0.1<=9.0.5
IBM WebSphere MQ=9.1.0.0
Remediation
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-1684.
2
What is the severity of CVE-2018-1684?
The severity of CVE-2018-1684 is medium, with a severity value of 6.5.
3
Which software versions are affected by CVE-2018-1684?
IBM WebSphere MQ versions 8.0.0.0 to 8.0.0.10, 9.0.0.0 to 9.0.0.5, 9.0.1 to 9.0.5, and 9.1.0.0 are affected by CVE-2018-1684.
4
What is the nature of the vulnerability in IBM WebSphere MQ?
The vulnerability in IBM WebSphere MQ is an error with MQTT topic string publishing that can cause a denial of service attack.
5
How can I fix CVE-2018-1684?
To fix CVE-2018-1684, apply the necessary security patches provided by IBM and upgrade to a non-vulnerable version of IBM WebSphere MQ.