PT-2016-2298 · Ibm · Websphere Mq
Publicado
2016-06-26
·
Atualizado
2016-11-30
·
CVE-2015-7473
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.4
Description
The issue is related to insufficient access control in the WebSphere MQ message processing service. It allows a local attacker to bypass existing access restrictions by leveraging authority for
+connect and +dsp.Recommendations
For IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.4, update to version 8.0.0.5 or later to resolve the issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Websphere Mq