4.3
CVSSv2

CVE-2010-2637

Published: 12/11/2010 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

IBM WebSphere MQ 6.0 prior to 6.0.2.9 and 7.0 prior to 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote malicious users to obtain sensitive information by sniffing the network traffic from a .NET client application.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere mq 6.0.2.2

ibm websphere mq 6.0

ibm websphere mq 6.0.2.0

ibm websphere mq 7.0.0.2

ibm websphere mq 7.0.1.0

ibm websphere mq 6.0.1.1

ibm websphere mq 6.0.1.0

ibm websphere mq 6.0.2.5

ibm websphere mq 7.0

ibm websphere mq 7.0.0.1

ibm websphere mq 6.0.2.3

ibm websphere mq 6.0.0.0

ibm websphere mq 6.0.2.7

ibm websphere mq 6.0.2.8

ibm websphere mq 6.0.2.1

ibm websphere mq 6.0.2.4

ibm websphere mq 6.0.2.10

ibm websphere mq 6.0.2.6