MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/29360 - | |
References | () http://securitytracker.com/id?1019610 - | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg21297035 - Patch | |
References | () http://www.securityfocus.com/bid/28235 - | |
References | () http://www.vupen.com/english/advisories/2008/0869 - |
Information
Published : 2008-03-31 23:44
Updated : 2024-11-21 00:44
NVD link : CVE-2008-1592
Mitre link : CVE-2008-1592
CVE.ORG link : CVE-2008-1592
JSON object : View
Products Affected
tandem_computers
- tandem_operating_system
ibm
- websphere_mq
hp
- nonstop
CWE
CWE-264
Permissions, Privileges, and Access Controls