Vulnerability Details CVE-2015-1957
IBM WebSphere MQ 7.5.x before 7.5.0.6 and 8.0.x before 8.0.0.3 allows remote authenticated users to obtain sensitive information via a man-in-the-middle attack, related to duplication of message data in cleartext outside the protected payload. IBM X-Force ID: 103482.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.5%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 3.5
Products affected by CVE-2015-1957
-
cpe:2.3:a:ibm:websphere_mq:7.5
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.0
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.1
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.2
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.3
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.4
-
cpe:2.3:a:ibm:websphere_mq:7.5.0.5
-
cpe:2.3:a:ibm:websphere_mq:8.0
-
cpe:2.3:a:ibm:websphere_mq:8.0.0.0
-
cpe:2.3:a:ibm:websphere_mq:8.0.0.1
-
cpe:2.3:a:ibm:websphere_mq:8.0.0.2