CVE-2011-1378

IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:websphere_mq:6.0:*:*:*:*:*:*:*
cpe:2.3:o:hp:openvms:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:26

Type Values Removed Values Added
References () http://secunia.com/advisories/46837 - Vendor Advisory () http://secunia.com/advisories/46837 - Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034 - () http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/71336 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/71336 -

Information

Published : 2011-11-26 03:57

Updated : 2024-11-21 01:26


NVD link : CVE-2011-1378

Mitre link : CVE-2011-1378

CVE.ORG link : CVE-2011-1378


JSON object : View

Products Affected

hp

  • openvms

ibm

  • websphere_mq
CWE
CWE-264

Permissions, Privileges, and Access Controls