VulnerabilityModified
CVE-2010-0782
IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.
MEDIUM 4.3EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere mq
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707
- http://www-01.ibm.com/support/docview.wss?uid=swg27014224
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60018
- http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707
- http://www-01.ibm.com/support/docview.wss?uid=swg27014224
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60018
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.