PT-2008-1666 · Ibm · Websphere Mq
Publicado
2008-03-09
·
Atualizado
2008-11-15
·
CVE-2007-6705
CVSS v2.0
3.3
Baixa
| Vetor | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WebSphere MQ XA versions 5.3 before FP13
WebSphere MQ XA versions 6.0.x before 6.0.2.1
Description
The issue allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process when the client is running in an MTS or a COM+ environment and connects to a queue manager, due to the granting of the PROCESS DUP HANDLE privilege to the Everyone group.
Recommendations
For WebSphere MQ XA versions 5.3 before FP13, apply FP13 to resolve the issue.
For WebSphere MQ XA versions 6.0.x before 6.0.2.1, update to version 6.0.2.1 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Websphere Mq