CVE-2011-1224
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue…
Does this matter?
Lower severity and a low EPSS score (0.77%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.77% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere mq
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg27007069
- http://www-01.ibm.com/support/docview.wss?uid=swg27014224
- http://www.ibm.com/support/docview.wss?uid=swg1IZ92813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68229
- http://www-01.ibm.com/support/docview.wss?uid=swg27007069
- http://www-01.ibm.com/support/docview.wss?uid=swg27014224
- http://www.ibm.com/support/docview.wss?uid=swg1IZ92813
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68229
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.