Origin validation error in paho.mqtt.java - CVE-2019-11777
Published: July 14, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
B2B Advanced Communications
Integration Bus for z/OS
IBM TXSeries for Multiplatforms
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM App Connect Enterprise
IBM CICS TX Advanced
IBM CICS TX Standard
How to mitigate CVE-2019-11777
B2B Advanced Communications - update to 1.0.0.10
Integration Bus for z/OS - update to 10.1.0.6
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.4.2
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.5.6, 8.6.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM Spectrum Protect Plus - update to 10.1.13
IBM CICS TX Standard - update to 11.1.0.0 ifix3
External References
Related Security Bulletins
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Origin validation error in IBM CICS TX Advanced
- Origin validation error in IBM CICS TX Standard
- Origin validation error in IBM Spectrum Protect Plus
- IBM B2B Advanced Communications update for paho.mqtt.java
- IBM TXSeries for Multiplatforms update for Eclipse Paho Java
- IBM App Connect Enterprise Toolkit and Intregation Bus for z/OS Toolkit update for Eclipse Paho Java