CVE-2011-1224

IBM WebSphere MQ 6.0-6.0.2.10 & 7.0-7.0.1.4 - Certificate Spoofing via Missing CRL Check

Title source: llm
STIX 2.1

Description

IBM WebSphere MQ 6.0 before 6.0.2.11 and 7.0 before 7.0.1.5 does not use the CRL Distribution Points (CDP) certificate extension, which might allow man-in-the-middle attackers to spoof an SSL partner via a revoked certificate for a (1) client, (2) queue manager, or (3) application.

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27007069
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014224
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68229
Various Sources vendor-advisory x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=swg1IZ92813

Scores

EPSS 0.0076
EPSS Percentile 51.7%

Details

CWE
CWE-264
Status published
Products (22)
ibm/websphere_mq 6.0
ibm/websphere_mq 6.0.1.0
ibm/websphere_mq 6.0.1.1
ibm/websphere_mq 6.0.2.0
ibm/websphere_mq 6.0.2.1
ibm/websphere_mq 6.0.2.2
ibm/websphere_mq 6.0.2.3
ibm/websphere_mq 6.0.2.4
ibm/websphere_mq 6.0.2.5
ibm/websphere_mq 6.0.2.6
... and 12 more
Published Jul 07, 2011
Tracked Since Feb 18, 2026