← Back

CVE-2010-2637

nvd nist
Published: Nov 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.

Affected (18)

Products: Ibm: Websphere Mq
1 product
Websphere Mq
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.0.0.0
Version 6.0.1.0
Version 6.0.1.1
Version 6.0.2.0
Version 6.0.2.10
Version 6.0.2.1
Version 6.0.2.2
Version 6.0.2.3
Version 6.0.2.4
Version 6.0.2.5
Version 6.0.2.6
Version 6.0.2.7
Version 6.0.2.8
Version 6.0
Version 7.0.0.1
Version 7.0.0.2
Version 7.0.1.0
Version 7.0

Related CWEs

Timeline

No history available yet.