PT-2008-3148 · Ibm · Websphere Mq

Publicado

2008-03-31

·

Atualizado

2011-03-08

·

CVE-2008-1592

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebSphere MQ versions 5.1 through 5.3.1
Description The issue allows local users to bypass intended access restrictions. This is related to the execution of administrative tasks without requiring mqm group membership, specifically via the runmqsc program, and is also related to "Pathway panels."
Recommendations For versions 5.1 through 5.3.1, consider restricting access to the runmqsc program to minimize the risk of exploitation. As a temporary workaround, ensure that only authorized users have access to execute administrative tasks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1592

Produtos afetados

Websphere Mq