First published: Mon Apr 15 2019(Updated: )
IBM WebShere MQ 9.1.0.0, 9.1.0.1, 9.1.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 152925.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | >=9.1.0.0<=9.1.0.1 | |
IBM WebSphere MQ | =9.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1925 is a vulnerability in IBM WebSphere MQ 9.1.0.0, 9.1.0.1, and 9.1.1 that allows an attacker to decrypt highly sensitive information.
CVE-2018-1925 allows an attacker to use weaker cryptographic algorithms to decrypt highly sensitive information within IBM WebSphere MQ.
CVE-2018-1925 has a severity rating of medium with a CVSS score of 5.9.
To fix CVE-2018-1925, users should upgrade to a version of IBM WebSphere MQ that does not use weaker cryptographic algorithms.
More information about CVE-2018-1925 can be found on IBM's support website and on the IBM X-Force Exchange.