VendorsIBMwebsphere_mq6.0.2.9
Vulnerabilities

IBM WebSphere MQ 6.0.2.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2011-0314
Heap-based buffer overflow in IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 allows remote authenticated users to execute arbitrary code or cause a denial of service (queue manager crash) by inserting an invalid message into the queue.
Published 2011-01-12 · Modified
6.5EPSS 0.030
CVE-2011-1224
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
Published 2011-07-07 · Modified
4.3EPSS 0.008
CVE-2010-0782
IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.
Published 2010-10-20 · Modified
4.3EPSS 0.007