CVE-2017-1283
published 2017-11-27CVE-2017-1283: IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of…
PriorityP418medium4.3CVSS 3.0
AVNACLPRLUINSUCNINAL
EPSS
0.94%
56.7th percentile
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p2xq-4649-mvv2: IBM WebSphere MQ 8
ghsa_unreviewed·2022-05-13
CVE-2017-1283 [MEDIUM] CWE-772 GHSA-p2xq-4649-mvv2: IBM WebSphere MQ 8
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a shared memory leak by MQ applications using dynamic queues, which can lead to lack of resources for other MQ applications. IBM X-Force ID: 125144.
OSV
apache2 vulnerabilities
osv·2018-04-19·CVSS 7.5
CVE-2017-15710 apache2 vulnerabilities
apache2 vulnerabilities
Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server
mod_authnz_ldap module incorrectly handled missing charset encoding
headers. A remote attacker could possibly use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2017-15710)
Elar Lang discovered that the Apache HTTP Server incorrectly handled
certain characters specified in . A remote attacker could
possibly use this issue to upload certain files, contrary to expectations.
(CVE-2017-15715)
It was discovered that the Apache HTTP Server mod_session module
incorrectly handled certain headers. A remote attacker could possibly use
this issue to influence session data. (CVE-2018-1283)
Robert Swiecki discovered that the Apache HTTP Server incorrectly handled
certain req
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-11-27
Published