Origin validation error in paho.mqtt.java - CVE-2019-11777

 

Origin validation error in paho.mqtt.java - CVE-2019-11777

Published: July 14, 2023


Vulnerability identifier: #VU78253
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11777
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

paho.mqtt.java
B2B Advanced Communications
Integration Bus for z/OS
IBM TXSeries for Multiplatforms
Maximo Manage Application in IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM App Connect Enterprise
IBM CICS TX Advanced
IBM CICS TX Standard

How to mitigate CVE-2019-11777

Install updates from vendor's website.

paho.mqtt.java - update to 1.2.1
B2B Advanced Communications - update to 1.0.0.10
Integration Bus for z/OS - update to 10.1.0.6
IBM App Connect Enterprise - addressed in versions 12.0.12.17, 13.0.4.2
Maximo Manage Application in IBM Maximo Application Suite - addressed in versions 8.5.6, 8.6.2
IBM CICS TX Advanced - addressed in versions 10.1.0.0 ifix10, 11.1.0.0 ifix3
IBM Spectrum Protect Plus - update to 10.1.13
IBM CICS TX Standard - update to 11.1.0.0 ifix3

External References

Related Security Bulletins