QID 375101
Date Published: 2021-03-24
QID 375101: IBM MQ Improper Access Controls Vulnerability(560861)
IBM WebSphere MQ is messaging for applications. It sends messages across networks of diverse components. Your application connects to IBM WebSphere MQ to send or receive a message. It is messaging and queuing middle-ware, with point-to-point, publish/subscribe, and file transfer modes of operation.
CVE-2016-6089: IBM WebSphere MQ could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access control.
Affected Versions:
IBM MQ v9.0.0.0
IBM MQ v9.0.1
QID Detection Logic (Authenticated):
Operating System: Linux
The QID executes /opt/mqm/bin/dspmqver -v | grep -A3 '^Name' to see if the system is running a vulnerable version of IBM MQ or not.
Successful exploitation of this vulnerability could allow an unauthorized user to write or delete files in a directory.
CVEs related to QID 375101
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 560861 |
|