IBM WebSphere MQ 7.0 / 7.1 / 7.5 Global Security Toolkit Vulnerabilities

High Nessus Plugin ID 63098


The remote Windows host has a service installed that has multiple vulnerabilities within the IBM Global Security Toolkit.


The version of IBM WebSphere MQ server is version 7.0 without Fix Pack, 7.1 without Fix Pack or 7.5 without Fix Pack It is, therefore, affected by the following vulnerabilities :

- A flaw exists in Global Security Kit (GSkit) due to a failure to properly validate data when the 'protection mechanism' is executed against an SSL CBC timing attack.
A remote attacker, using crafted values in the TLS Record Layer, can exploit this to cause a denial of service.

- A flaw exists in Global Security Kit (GSkit) due to a failure to properly verify certificates, which can allow a remote attacker to conduct a man-in-the-middle attack.


Apply fix pack or later.

See Also

Plugin Details

Severity: High

ID: 63098

File Name: websphere_mq_7010_7019.nasl

Version: $Revision: 1.5 $

Type: local

Agent: windows

Family: Windows

Published: 2012/11/29

Modified: 2016/05/06

Dependencies: 57708

Risk Information

Risk Factor: High


Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:ibm:websphere_mq

Required KB Items: installed_sw/IBM WebSphere MQ

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2012/11/26

Vulnerability Publication Date: 2012/07/30

Reference Information

CVE: CVE-2012-2191, CVE-2012-2203

BID: 54743

OSVDB: 84473, 84474