Vulnerability Bulletins

IBM Security Bulletin: IBM MQ Light - Potential authentication bypass vulnerability when using the JAASConfig property (CVE-2014-6116)

   
Affected software IBM
 
IBM MQ Light contains a vulnerability in which authentication is bypassed by MQTT clients with the "JAASConfig" configuration property set. CVE(s): CVE-2014-6116 Affected product(s) and affected version(s): IBM MQ Light V1.0 on all platforms. The version of IBM MQ Light can be determined by running "mqlight-config --version". A V1.0 installation will return text containing: Name: IBM MQ Light Version: 1.0 Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_mq_light_potential_authentication_bypass_vulnerability_when_using_the_jaasconfig_property_cve_2014_6116?lang=en_us