CVE-2017-1318
UnknownEPSS 3.14%
Last modified
CVE-2017-1318 is a vulnerability of currently unknown severity. IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.. EPSS estimates a 3.14% chance of exploitation in the next 30 days.
Description
IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Mq Appliance | 8.0.0.0 |
| Ibm | Mq Appliance | 8.0.0.1 |
| Ibm | Mq Appliance | 8.0.0.2 |
| Ibm | Mq Appliance | 8.0.0.3 |
| Ibm | Mq Appliance | 8.0.0.4 |
| Ibm | Mq Appliance | 8.0.0.5 |
| Ibm | Mq Appliance | 8.0.0.6 |
| Ibm | Mq Appliance | 9.0.1 |
| Ibm | Mq Appliance | 9.0.2 |
References
- http://www.ibm.com/support/docview.wss?uid=swg22003815Vendor Advisory
- http://www.securityfocus.com/bid/99594Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125730VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22003815Vendor Advisory
- http://www.securityfocus.com/bid/99594Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125730VDB Entry, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1318?
IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the system, caused by command execution. IBM X-Force ID: 125730.
How severe is CVE-2017-1318?
Severity scoring for CVE-2017-1318 is pending analysis. The EPSS model estimates a 3.14% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1318?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-13174An elevation of privilege vulnerability in the kernel edl. P…
- CVE-2017-13175An information disclosure vulnerability in the NVIDIA libwil…
- CVE-2017-13176In the parseURL function of URLStreamHandler, there is impro…
- CVE-2017-13177In several functions of libhevc, NEON registers are not pres…
- CVE-2017-13178In the initDecoder function of SoftAVCDec, there is a possib…
- CVE-2017-13179In the ihevcd_allocate_static_bufs and ihevcd_create functio…
- CVE-2017-13180In the onQueueFilled function of SoftAVCDec, there is a poss…
- CVE-2017-13181In the doGetThumb and getThumbnail functions of MtpServer, t…
- CVE-2017-13182In the sendFormatChange function of ACodec, there is a possi…
- CVE-2017-13183In the OMXNodeInstance::useBuffer and IOMX::freeBuffer funct…
- CVE-2017-13184In the enableVSyncInjections function of SurfaceFlinger, the…
- CVE-2017-13185An information disclosure vulnerability in the Android media…
Are you affected by CVE-2017-1318?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
