QID 376108
Date Published: 2021-11-30
QID 376108: IBM MQ Arbitrary Code Execution Vulnerability (6513983)
IBM MQ is a message oriented middleware that allows independent and non-concurrent applications on a distributed system to communicate with each other.
Eclipse could allow a local attacker to execute arbitrary commands on the system, caused by the failure to authenticate active help requests to the local help web server.
Affected Version:
IBM MQ 9.0.0, 9.1.0, 9.2.0
QID Detection Logic: (Authenticated)
Operating System: Linux
The QID runs the command "/opt/mqm/bin/dspmqver -v | grep -A3 '^Name'" and "/usr/mqm/bin/dspmqver -v | grep -A3 '^Name'" (for AIX only) to see if the system is running a vulnerable version of IBM MQ or not.
Operating System: Windows
It checks for vulnerable IBM MQ/WebSphere MQ versions.
An attacker could exploit this vulnerability to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
- 6513983 -
www.ibm.com/support/pages/node/6513983
CVEs related to QID 376108
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6513983 |
|