PT-2019-16887 · Ibm · Ibm Websphere Mq
Publicado
2019-05-23
·
Atualizado
2022-12-09
·
CVE-2019-4078
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.9
IBM WebSphere MQ versions 9.0.0.0 through 9.1.1
Description
The issue allows a local non-privileged user to execute code as an administrator due to incorrect permissions set on MQ installation directories.
Recommendations
For IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.9, update the permissions on MQ installation directories to prevent local non-privileged users from executing code as an administrator.
For IBM WebSphere MQ versions 9.0.0.0 through 9.1.1, update the permissions on MQ installation directories to prevent local non-privileged users from executing code as an administrator.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Websphere Mq