Boletines de Vulnerabilidades

IBM Security Bulletin: IBM WebSphere MQ is affected by a vulnerability in the WebSphere MQ classes for Java libraries and WebSphere MQ Explorer (CVE-2014-4822)


Información sobre el sistema

   
Software afectado IBM

Descripción

A vulnerability in the WebSphere MQ classes for Java libraries and WebSphere MQ Explorer can potentially allow preconfigured passwords to be traced in plain text. CVE(s): CVE-2014-4822 Affected product(s) and affected version(s): WebSphere MQ classes for Java libraries, included in; WebSphere MQ 8 WebSphere MQ Explorer available in; WebSphere MQ 7.5 (maintenance levels older than 7.5.0.5) WebSphere MQ 8 (maintenance levels older than 8.0.0.2) Refer to the following reference

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_websphere_mq_is_affected_by_a_vulnerability_in_the_websphere_mq_classes_for_java_libraries_and_websphere_mq_explorer_cve_2014_4822?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-4822 ,CVE-2014-6271 ,CVE-2014-7169 ,CVE-2014-7191 ,CVE-2014-7186 ,CVE-2014-7187 ,CVE-2014-6277 and CVE-2014-6278.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2014-10-15

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT