CVE-2008-1592

MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:hp:nonstop:*:*:*:*:*:*:*:*
cpe:2.3:o:tandem_computers:tandem_operating_system:nsk:*:*:*:*:*:*:*
OR cpe:2.3:a:ibm:websphere_mq:5.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:5.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:5.3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:44

Type Values Removed Values Added
References () http://secunia.com/advisories/29360 - () http://secunia.com/advisories/29360 -
References () http://securitytracker.com/id?1019610 - () http://securitytracker.com/id?1019610 -
References () http://www-1.ibm.com/support/docview.wss?uid=swg21297035 - Patch () http://www-1.ibm.com/support/docview.wss?uid=swg21297035 - Patch
References () http://www.securityfocus.com/bid/28235 - () http://www.securityfocus.com/bid/28235 -
References () http://www.vupen.com/english/advisories/2008/0869 - () http://www.vupen.com/english/advisories/2008/0869 -

Information

Published : 2008-03-31 23:44

Updated : 2024-11-21 00:44


NVD link : CVE-2008-1592

Mitre link : CVE-2008-1592

CVE.ORG link : CVE-2008-1592


JSON object : View

Products Affected

tandem_computers

  • tandem_operating_system

ibm

  • websphere_mq

hp

  • nonstop
CWE
CWE-264

Permissions, Privileges, and Access Controls