CVE-2012-2199
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors…
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
The server message channel agent in the queue manager in the server in IBM WebSphere MQ 7.0.1 before 7.0.1.9, 7.1, and 7.5 on Solaris allows remote attackers to cause a denial of service (invalid address alignment exception and daemon crash) via vectors involving a multiplexed channel.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- ibm/websphere mq
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC82725
- http://www.ibm.com/support/docview.wss?uid=swg21610285Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76434
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC82725
- http://www.ibm.com/support/docview.wss?uid=swg21610285Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76434
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.