CVE-2012-5953: IBM WebSphere Message Broker

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2, when the Parse Query Strings option is enabled on an HTTPInput node, allows remote attackers to cause a denial of service (infinite loop) via a crafted query string.

Affected products

  • IBM WebSphere Message Broker: version 6.1 only; version 6.1.0.1 only; version 6.1.0.2 only; version 6.1.0.3 only; version 6.1.0.4 only; version 6.1.0.5 only; …

Published 2013-02-20. Last modified 2026-06-16.