IBM MQ Appliance has addressed the following MIT Kerberos 5 (aka krb5) vulnerability.
CVEID:CVE-2017-11462
**DESCRIPTION:**Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/132060 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM MQ Appliance | 8.0 |
IBM MQ Appliance | 9.1 LTS |
IBM MQ Appliance | 9.1 CD |
IBM MQ Appliance 8
Apply fix pack 8.0.0.14, or later.
IBM MQ Appliance version 9.1 LTS
Apply fix pack 9.1.0.4, or later.
IBM MQ Appliance version 9.1 CD
Apply continuous delivery release 9.1.4, or later.
None