http://www.wikio.fr WebSphere And Tivoli Tricks: WebSphere MQ Security Vulnerability: potential buffer overflow on unsecured WebSphere MQ client connections

Monday, April 2, 2012

WebSphere MQ Security Vulnerability: potential buffer overflow on unsecured WebSphere MQ client connections

Abstract

WebSphere MQ Security Vulnerability: There is a potential buffer overflow which can occur when the MQ server is processing inbound data on a client connection.

Content

There is a potential buffer overflow which can occur when the MQ server is processing inbound data on a client connection.

This exposure applies to all WebSphere MQ V6 and higher queue managers and resolution will ship in 6.0.2.7 and 7.0.1.0. This issue is not present in releases prior to WebSphere MQ V6.

Links to associated interim fixes can be found here:
http://www.ibm.com/support/docview.wss?rs=171&uid=swg24023135

Vulnerability information:
http://xforce.iss.net/xforce/xfdb/50641

Unauthorized users are unable to exploit this on any queue manager which is secured with SSL and/or authentication security exits.

No comments:

Post a Comment