Lucene search

K
cve[email protected]CVE-2011-1224
HistoryJul 07, 2011 - 9:55 p.m.

CVE-2011-1224

2011-07-0721:55:01
CWE-264
web.nvd.nist.gov
21
ibm websphere mq
crl distribution points
ssl partner spoofing
certificate extension
cve-2011-1224
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.8%

IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.

Affected configurations

NVD
Node
ibmwebsphere_mqMatch6.0
OR
ibmwebsphere_mqMatch6.0.1.0
OR
ibmwebsphere_mqMatch6.0.1.1
OR
ibmwebsphere_mqMatch6.0.2.0
OR
ibmwebsphere_mqMatch6.0.2.1
OR
ibmwebsphere_mqMatch6.0.2.2
OR
ibmwebsphere_mqMatch6.0.2.3
OR
ibmwebsphere_mqMatch6.0.2.4
OR
ibmwebsphere_mqMatch6.0.2.5
OR
ibmwebsphere_mqMatch6.0.2.6
OR
ibmwebsphere_mqMatch6.0.2.7
OR
ibmwebsphere_mqMatch6.0.2.8
OR
ibmwebsphere_mqMatch6.0.2.9
OR
ibmwebsphere_mqMatch6.0.2.10
Node
ibmwebsphere_mqMatch7.0
OR
ibmwebsphere_mqMatch7.0.0.1
OR
ibmwebsphere_mqMatch7.0.0.2
OR
ibmwebsphere_mqMatch7.0.1.0
OR
ibmwebsphere_mqMatch7.0.1.1
OR
ibmwebsphere_mqMatch7.0.1.2
OR
ibmwebsphere_mqMatch7.0.1.3
OR
ibmwebsphere_mqMatch7.0.1.4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.8%

Related for CVE-2011-1224