CVE-2015-7421
low
CVSS v3
3.7
CVSS v2
5.0
VIR risk
3.7
Description
Unspecified vulnerability in GSKit on IBM MQ M2000 appliances before 8.0.0.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2015-7420.
Predictions
Exploit likelihood
47%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21971500
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | mq_appliance_m2000 | {"endIncluding":"8.0.0.3"} | |
References
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1023277
- http://www-01.ibm.com/support/docview.wss?uid=swg21971500
- http://www.securityfocus.com/bid/82303
- http://www.securitytracker.com/id/1034846
- http://www-01.ibm.com/support/docview.wss?uid=isg3T1023277
- http://www-01.ibm.com/support/docview.wss?uid=swg21971500
- http://www.securityfocus.com/bid/82303
- http://www.securitytracker.com/id/1034846
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.