PT-2008-3148 · Ibm · Websphere Mq

Published

2008-03-31

·

Updated

2011-03-08

·

CVE-2008-1592

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebSphere MQ versions 5.1 through 5.3.1
Description The issue allows local users to bypass intended access restrictions. This is related to the execution of administrative tasks without requiring mqm group membership, specifically via the runmqsc program, and is also related to "Pathway panels."
Recommendations For versions 5.1 through 5.3.1, consider restricting access to the runmqsc program to minimize the risk of exploitation. As a temporary workaround, ensure that only authorized users have access to execute administrative tasks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1592

Affected Products

Websphere Mq