IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2010-11-12 13:00
Updated : 2017-08-16 18:32
NVD link : CVE-2010-2637
Mitre link : CVE-2010-2637
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
ibm
- websphere_mq