IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/46837 - Vendor Advisory | |
References | () http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/71336 - |
Information
Published : 2011-11-26 03:57
Updated : 2024-11-21 01:26
NVD link : CVE-2011-1378
Mitre link : CVE-2011-1378
CVE.ORG link : CVE-2011-1378
JSON object : View
Products Affected
hp
- openvms
ibm
- websphere_mq
CWE
CWE-264
Permissions, Privileges, and Access Controls