4.3

CVE-2011-1224

IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmWebsphere Mq Version6.0
IbmWebsphere Mq Version6.0.1.0
IbmWebsphere Mq Version6.0.1.1
IbmWebsphere Mq Version6.0.2.0
IbmWebsphere Mq Version6.0.2.1
IbmWebsphere Mq Version6.0.2.2
IbmWebsphere Mq Version6.0.2.3
IbmWebsphere Mq Version6.0.2.4
IbmWebsphere Mq Version6.0.2.5
IbmWebsphere Mq Version6.0.2.6
IbmWebsphere Mq Version6.0.2.7
IbmWebsphere Mq Version6.0.2.8
IbmWebsphere Mq Version6.0.2.9
IbmWebsphere Mq Version6.0.2.10
IbmWebsphere Mq Version7.0
IbmWebsphere Mq Version7.0.0.1
IbmWebsphere Mq Version7.0.0.2
IbmWebsphere Mq Version7.0.1.0
IbmWebsphere Mq Version7.0.1.1
IbmWebsphere Mq Version7.0.1.2
IbmWebsphere Mq Version7.0.1.3
IbmWebsphere Mq Version7.0.1.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.318
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N