PT-2016-2284 · Ibm · Websphere Mq

Published

2016-06-19

·

Updated

2016-11-30

·

CVE-2015-7462

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere MQ version 8.0.0.4
Description The issue is related to errors in handling registration data in the WebSphere MQ message processing service. It may allow a local attacker to elevate privileges using the mqcertck tool. Additionally, the vulnerability can be exploited by local users with administrator privileges to discover cleartext certificate-keystore passwords within MQ trace output by executing the mqcertck program.
Recommendations For IBM WebSphere MQ version 8.0.0.4, consider restricting access to the mqcertck tool to prevent local users from exploiting the issue. As a temporary workaround, limit the execution of the mqcertck program to necessary administrative tasks only.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01673
CVE-2015-7462

Affected Products

Websphere Mq