CVE-2009-3160
Summary
| CVE | CVE-2009-3160 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-10 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue. |
Risk And Classification
Primary CVSS: v2.0 8.8 from [email protected]
AV:N/AC:M/Au:N/C:N/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:N/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Mq | 6 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.0.0 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.1.0 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.1.1 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.0 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.1 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.2 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.3 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.4 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.5 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.6 | All | All | All |
| Application | Ibm | Websphere Mq | 6.0.2.7 | All | All | All |
| Application | Ibm | Websphere Mq | 7.0.0.0 | All | All | All |
| Application | Ibm | Websphere Mq | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Mq | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Mq | 7.0.1.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Combined fix for security vulnerability APARs IC62164, IC62450 and IZ56259 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM WebSphere MQ Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM WebSphere MQ Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.