PT-2008-1666 · Ibm · Websphere Mq

Publicado

2008-03-09

·

Atualizado

2008-11-15

·

CVE-2007-6705

CVSS v2.0

3.3

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebSphere MQ XA versions 5.3 before FP13 WebSphere MQ XA versions 6.0.x before 6.0.2.1
Description The issue allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process when the client is running in an MTS or a COM+ environment and connects to a queue manager, due to the granting of the PROCESS DUP HANDLE privilege to the Everyone group.
Recommendations For WebSphere MQ XA versions 5.3 before FP13, apply FP13 to resolve the issue. For WebSphere MQ XA versions 6.0.x before 6.0.2.1, update to version 6.0.2.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6705

Produtos afetados

Websphere Mq