PT-2018-12346 · Ibm · Ibm Websphere Mq
Published
2018-06-15
·
Updated
2019-10-09
·
CVE-2018-1419
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere MQ versions 8.0 through 9.0
Description
The issue allows a user to cause a deadlock in the IBM MQ PAM code, resulting in a denial of service, when IBM WebSphere MQ is configured to use a PAM module for authentication.
Recommendations
For IBM WebSphere MQ versions 8.0 through 9.0, consider reconfiguring the authentication settings to avoid using the PAM module until a fix is available. As a temporary workaround, restrict access to the PAM authentication module to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Websphere Mq