IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Websphere_mq_jms | Ibm | 7.0.1 (including) | 7.0.1 (including) |
Websphere_mq_jms | Ibm | 7.1 (including) | 7.1 (including) |
Websphere_mq_jms | Ibm | 7.5 (including) | 7.5 (including) |
Websphere_mq_jms | Ibm | 8.0 (including) | 8.0 (including) |
Websphere_mq_jms | Ibm | 9.0 (including) | 9.0 (including) |