PT-2016-2284 · Ibm · Websphere Mq
Published
2016-06-19
·
Updated
2016-11-30
·
CVE-2015-7462
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere MQ version 8.0.0.4
Description
The issue is related to errors in handling registration data in the WebSphere MQ message processing service. It may allow a local attacker to elevate privileges using the
mqcertck tool. Additionally, the vulnerability can be exploited by local users with administrator privileges to discover cleartext certificate-keystore passwords within MQ trace output by executing the mqcertck program.Recommendations
For IBM WebSphere MQ version 8.0.0.4, consider restricting access to the
mqcertck tool to prevent local users from exploiting the issue. As a temporary workaround, limit the execution of the mqcertck program to necessary administrative tasks only.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Websphere Mq