PT-2009-5476 · Ibm · Ibm Websphere Mq

Published

2009-09-10

·

Updated

2009-10-01

·

CVE-2009-3160

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IBM WebSphere MQ versions 6.x through 6.0.2.7 IBM WebSphere MQ versions 7.0.0.0 through 7.0.1.0
Description: The issue is related to a "memory overwrite" problem when read ahead or asynchronous message consumption is enabled, allowing attackers to have an unspecified impact via unknown vectors.
Recommendations: For IBM WebSphere MQ versions 6.x through 6.0.2.7, update to a version outside of the affected range to resolve the issue. For IBM WebSphere MQ versions 7.0.0.0 through 7.0.1.0, update to a version outside of the affected range to resolve the issue. As a temporary workaround, consider disabling read ahead or asynchronous message consumption until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-3160

Affected Products

Ibm Websphere Mq