PT-2016-2284 · Ibm · Websphere Mq
Publicado
2016-06-19
·
Atualizado
2016-11-30
·
CVE-2015-7462
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere MQ version 8.0.0.4
Description
The issue is related to errors in handling registration data in the WebSphere MQ message processing service. It may allow a local attacker to elevate privileges using the
mqcertck tool. Additionally, the vulnerability can be exploited by local users with administrator privileges to discover cleartext certificate-keystore passwords within MQ trace output by executing the mqcertck program.Recommendations
For IBM WebSphere MQ version 8.0.0.4, consider restricting access to the
mqcertck tool to prevent local users from exploiting the issue. As a temporary workaround, limit the execution of the mqcertck program to necessary administrative tasks only.Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Websphere Mq