CVE-2011-1224 Information
Feb 14, 2021
cve
Description
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client (2) queue manager or (3) application.
Reference
http://www.ibm.com/support/docview.wss?uid=swg1IZ92813 http://www-01.ibm.com/support/docview.wss?uid=swg27007069 http://www-01.ibm.com/support/docview.wss?uid=swg27014224 https://exchange.xforce.ibmcloud.com/vulnerabilities/68229
Share on: