QID 375394
Date Published: 2021-03-24
QID 375394: IBM MQ Insecure File Permission Vulnerability(299299)
IBM WebSphere MQ is messaging for applications. It sends messages across networks of diverse components. Your application connects to IBM WebSphere MQ to send or receive a message. It is messaging and queuing middle-ware, with point-to-point, publish/subscribe, and file transfer modes of operation.
CVE-2017-1699: An IBM WebSphere MQ or IBM MQ Managed File Transfer agent sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact.
Affected Versions:
WebSphere MQ V8.0.0.0 to V8.0.0.6
IBM MQ LTS V9.0.0.0 to V9.0.0.1
IBM MQ CD V9.0.1 to V9.0.3
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
Successful exploitation of this vulnerability could allow a local attacker to modify or delete data contained in the files with an unknown impact.
CVEs related to QID 375394
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 299299 |
|