IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
BID:50461
Info
IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
| Bugtraq ID: | 50461 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-0905 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 05 2009 12:00AM |
| Updated: | Jun 05 2009 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere MQ 7.0 2 IBM WebSphere MQ 6.0.2 .7 IBM WebSphere MQ 6.0.2 .6 IBM WebSphere MQ 6.0.2 .5 IBM WebSphere MQ 6.0.2 .4 IBM WebSphere MQ 6.0.2 .3 IBM WebSphere MQ 6.0.2 .2 IBM WebSphere MQ 6.0.2 .1 IBM WebSphere MQ 7.0.0.1 IBM WebSphere MQ 6.0.2.0 |
| Not Vulnerable: |
IBM WebSphere MQ 7.0.1.0 IBM WebSphere MQ 6.0.2.8 |
Discussion
IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
IBM WebSphere MQ is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Attackers can exploit this issue to bypass certain security restrictions and potentially gain elevated privileges.
IBM WebSphere MQ is prone to a security-bypass vulnerability because the application fails to properly restrict access to certain functionality.
Attackers can exploit this issue to bypass certain security restrictions and potentially gain elevated privileges.
Exploit / POC
IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
An attacker will likely use standard tools to exploit this issue.
An attacker will likely use standard tools to exploit this issue.
Solution / Fix
IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
Solution:
The vendor has released an advisory and updates. Please see the references for more information.
References
IBM WebSphere MQ Group Names Local Security Bypass Vulnerability
References:
References: