VulnerabilityModified
CVE-2019-4261
IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages.
MEDIUM 6.5EPSS 2.35%
Does this matter?
Lower severity and a low EPSS score (2.35%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of service attack caused by specially crafted messages. IBM X-Force ID: 160013.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.35% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- ibm/mq · ibm/websphere mq
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/160013VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10886887Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/160013VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10886887Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.