Vulnerability Name:

CVE-2011-1224 (CCN-68229)

Assigned:2011-06-15
Published:2011-06-15
Updated:2017-08-17
Summary:IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-264
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2011-1224

Source: CCN
Type: IBM APAR IZ92813
WebSphere MQ V7.0 Fix Pack 7.0.1.5

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg27007069

Source: CONFIRM
Type: UNKNOWN
http://www-01.ibm.com/support/docview.wss?uid=swg27014224

Source: AIXAPAR
Type: UNKNOWN
IZ92813

Source: CCN
Type: OSVDB ID: 73704
IBM WebSphere MQ CDP Certificate Extension Revoked Certificate MiTM SSL Partner Spoofing Weakness

Source: CCN
Type: BID-48636
IBM WebSphere MQ CDP Extension Revoked SSL Certificate Validation Security Bypass Vulnerability

Source: XF
Type: UNKNOWN
websphere-mq-cdb-security-bypass(68229)

Source: XF
Type: UNKNOWN
websphere-mq-cdb-security-bypass(68229)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:websphere_mq:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.9:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:6.0.2.10:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:ibm:websphere_mq:7.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0.1.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:websphere_mq:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:websphere_mq:7.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm websphere mq 6.0
    ibm websphere mq 6.0.1.0
    ibm websphere mq 6.0.1.1
    ibm websphere mq 6.0.2.0
    ibm websphere mq 6.0.2.1
    ibm websphere mq 6.0.2.2
    ibm websphere mq 6.0.2.3
    ibm websphere mq 6.0.2.4
    ibm websphere mq 6.0.2.5
    ibm websphere mq 6.0.2.6
    ibm websphere mq 6.0.2.7
    ibm websphere mq 6.0.2.8
    ibm websphere mq 6.0.2.9
    ibm websphere mq 6.0.2.10
    ibm websphere mq 7.0
    ibm websphere mq 7.0.0.1
    ibm websphere mq 7.0.0.2
    ibm websphere mq 7.0.1.0
    ibm websphere mq 7.0.1.1
    ibm websphere mq 7.0.1.2
    ibm websphere mq 7.0.1.3
    ibm websphere mq 7.0.1.4
    ibm websphere mq 6.0
    ibm websphere mq 7.0