IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
BID:28235
Info
IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
| Bugtraq ID: | 28235 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1592 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 11 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
IBM WebSphere MQ for HP NonStop 5.1 |
| Not Vulnerable: |
IBM WebSphere MQ for HP NonStop 5.3.1 IBM WebSphere MQ for HP NonStop 5.3 |
Discussion
IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
IBM WebSphere MQ for HP NonStop Server (NSS) is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Unauthorized attackers can exploit this issue to bypass certain security restrictions and carry out some administrative tasks. This may lead to various attacks.
This issue affects versions prior to WebSphere MQ for HP NSS 5.3.
IBM WebSphere MQ for HP NonStop Server (NSS) is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Unauthorized attackers can exploit this issue to bypass certain security restrictions and carry out some administrative tasks. This may lead to various attacks.
This issue affects versions prior to WebSphere MQ for HP NSS 5.3.
Exploit / POC
IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
An attacker will likely use standard tools to exploit this issue.
An attacker will likely use standard tools to exploit this issue.
Solution / Fix
IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
Solution:
The vendor released an advisory and updates to address this issue. Please see the references for more information.
References
IBM WebSphere MQ for HP NonStop Security Bypass Vulnerability
References:
References: