PT-2016-4169 · Ibm · Ibm Messagesight

Matthias Kaiser

·

Published

2016-07-01

·

Updated

2016-07-08

·

CVE-2016-0375

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM MessageSight versions 1.1.x through 1.1.0.1 IBM MessageSight versions 1.2.x through 1.2.0.3 IBM MessageSight versions 2.0.x through 2.0.0.0
Description The JMS Client in IBM MessageSight allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.
Recommendations For IBM MessageSight versions 1.1.x through 1.1.0.1, update to a version outside of this range to mitigate the risk. For IBM MessageSight versions 1.2.x through 1.2.0.3, update to a version outside of this range to mitigate the risk. For IBM MessageSight versions 2.0.x through 2.0.0.0, update to a version outside of this range to mitigate the risk.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0375

Affected Products

Ibm Messagesight