IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IZ56005 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg27007069 - | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg27014224 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/63114 - |
Information
Published : 2010-11-12 21:00
Updated : 2024-11-21 01:17
NVD link : CVE-2010-2637
Mitre link : CVE-2010-2637
CVE.ORG link : CVE-2010-2637
JSON object : View
Products Affected
ibm
- websphere_mq
CWE
CWE-310
Cryptographic Issues