CVE-2014-6116

IBM Websphere MQ - Authentication Bypass

Title source: rule

Description

The Telemetry Component in WebSphere MQ 8.0.0.1 before p000-001-L140910 allows remote attackers to bypass authentication by setting the JAASConfig property in an MQTT client configuration.

Scores

EPSS 0.0021
EPSS Percentile 42.8%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

ibm/websphere_mq

Timeline

Published Oct 19, 2014
Tracked Since Feb 18, 2026