MEDIUM · 4.3

CVE-2015-0173

The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier...

Vulnerability Description

The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier for remote attackers to bypass intended restrictions on MQ message data by predicting an ID value.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmWebsphere Mq Internet Pass Thru<= 2.1.0.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0173?

CVE-2015-0173 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The HTTP connection-management functionality in Internet Pass-Thru (IPT) before 2.1.0.2 in IBM WebSphere MQ, when HTTPS is disabled, does not properly generate MQIPT Session IDs, which makes it easier...

How severe is CVE-2015-0173?

CVE-2015-0173 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0173?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Websphere Mq Internet Pass Thru.