IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 01:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.ibm.com/support/docview.wss?uid=swg1IZ37102 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/51042 - |
Information
Published : 2011-10-30 19:55
Updated : 2024-11-21 01:01
NVD link : CVE-2009-0905
Mitre link : CVE-2009-0905
CVE.ORG link : CVE-2009-0905
JSON object : View
Products Affected
ibm
- websphere_mq
CWE
CWE-20
Improper Input Validation