IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/105040 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/142888 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10716113 | Vendor Advisory |
http://www.securityfocus.com/bid/105040 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/142888 | VDB Entry Vendor Advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10716113 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/105040 - Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/142888 - VDB Entry, Vendor Advisory | |
References | () https://www.ibm.com/support/docview.wss?uid=ibm10716113 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.0
v3 : 3.1 |
Information
Published : 2018-08-06 14:29
Updated : 2024-11-21 04:00
NVD link : CVE-2018-1551
Mitre link : CVE-2018-1551
CVE.ORG link : CVE-2018-1551
JSON object : View
Products Affected
ibm
- websphere_mq
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource