Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=swg21998660 | patch vendor advisory |
http://www.securityfocus.com/bid/96400 | vdb entry |