Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-0118


IBM WebSphere Message Broker Toolkit 7 before 7007 IF2 and 8 before 8005 IF1 and Integration Toolkit 9 before 9003 IF1 are distributed with MQ client JAR files that support only weak TLS ciphers, which might make it easier for remote attackers to obtain sensitive information by sniffing the network during a connection to an Integration Bus node.


Published

2015-06-28T22:59:03.410

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm websphere_message_broker 7.0. Yes
Application ibm websphere_message_broker 7.0.0.1 Yes
Application ibm websphere_message_broker 7.0.0.2 Yes
Application ibm websphere_message_broker 7.0.0.3 Yes
Application ibm websphere_message_broker 7.0.0.4 Yes
Application ibm websphere_message_broker 7.0.0.5 Yes
Application ibm websphere_message_broker 8.0 Yes
Application ibm websphere_message_broker 8.0.0.1 Yes
Application ibm websphere_message_broker 8.0.0.2 Yes
Application ibm websphere_message_broker 8.0.0.3 Yes
Application ibm websphere_message_broker 8.0.0.4 Yes
Application ibm websphere_message_broker 8.0.0.5 Yes
Application ibm integration_bus 9.0 Yes
Application ibm integration_bus 9.0.0.1 Yes
Application ibm integration_bus 9.0.0.2 Yes
Application ibm integration_bus 9.0.0.3 Yes

References