PT-2016-2284 · Ibm · Websphere Mq

Publicado

2016-06-19

·

Atualizado

2016-11-30

·

CVE-2015-7462

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere MQ version 8.0.0.4
Description The issue is related to errors in handling registration data in the WebSphere MQ message processing service. It may allow a local attacker to elevate privileges using the mqcertck tool. Additionally, the vulnerability can be exploited by local users with administrator privileges to discover cleartext certificate-keystore passwords within MQ trace output by executing the mqcertck program.
Recommendations For IBM WebSphere MQ version 8.0.0.4, consider restricting access to the mqcertck tool to prevent local users from exploiting the issue. As a temporary workaround, limit the execution of the mqcertck program to necessary administrative tasks only.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01673
CVE-2015-7462

Produtos afetados

Websphere Mq