CVE-2011-1224
IBM WebSphere MQ 6.0-6.0.2.10 & 7.0-7.0.1.4 - Certificate Spoofing via Missing CRL Check
Title source: llmDescription
IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.
References (4)
Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27007069
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014224
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68229
Various Sources vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1IZ92813
Scores
EPSS
0.0076
EPSS Percentile
51.7%
Details
CWE
CWE-264
Status
published
Products (22)
ibm/websphere_mq
6.0
ibm/websphere_mq
6.0.1.0
ibm/websphere_mq
6.0.1.1
ibm/websphere_mq
6.0.2.0
ibm/websphere_mq
6.0.2.1
ibm/websphere_mq
6.0.2.2
ibm/websphere_mq
6.0.2.3
ibm/websphere_mq
6.0.2.4
ibm/websphere_mq
6.0.2.5
ibm/websphere_mq
6.0.2.6
... and 12 more
Published
Jul 07, 2011
Tracked Since
Feb 18, 2026