IBM WebSphere MQ Security Bypass Vulnerability
BID:28046
Info
IBM WebSphere MQ Security Bypass Vulnerability
| Bugtraq ID: | 28046 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1130 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 29 2008 12:00AM |
| Updated: | May 07 2008 07:15PM |
| Credit: | The vendor credits the Security Assurance Team of the National Australia Bank |
| Vulnerable: |
IBM WebSphere MQ 5.3 IBM WebSphere MQ 6 |
| Not Vulnerable: |
IBM WebSphere MQ 6.0.2 .2 IBM WebSphere MQ 5.3 Fix Pack 14 |
Discussion
IBM WebSphere MQ Security Bypass Vulnerability
IBM WebSphere MQ is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Attackers can exploit this issue to bypass certain security restrictions, connect to a queue manager in an unauthorized manner, and obtain potentially sensitive information; other attacks are also possible.
This issue affects versions prior to:
5.3 Fix Pack 14
6.0 Fix Pack 6.0.2.2
IBM WebSphere MQ is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Attackers can exploit this issue to bypass certain security restrictions, connect to a queue manager in an unauthorized manner, and obtain potentially sensitive information; other attacks are also possible.
This issue affects versions prior to:
5.3 Fix Pack 14
6.0 Fix Pack 6.0.2.2
Exploit / POC
IBM WebSphere MQ Security Bypass Vulnerability
An attacker will likely use standard tools to exploit this issue.
An attacker will likely use standard tools to exploit this issue.
Solution / Fix
IBM WebSphere MQ Security Bypass Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
IBM WebSphere MQ Security Bypass Vulnerability
References:
References:
- WebSphere MQ (IBM)
- WebSphere MQ Security White Paper �?? Part 1 (MWR InfoSecurity)
- IZ01272: Potential security exposure in MQ client channels (IBM)
- Websphere MQ MCAUSER Setting Bypass Vulnerability (MWR InfoSecurity)
- WepSphere MQ Security Exit Authentication Bypass Vulnerability (MWR InfoSecurity)