CVE-2018-1551

IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:websphere_mq:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:00

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/105040 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/105040 - Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/142888 - Vendor Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/142888 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/docview.wss?uid=ibm10716113 - Vendor Advisory () https://www.ibm.com/support/docview.wss?uid=ibm10716113 - Vendor Advisory
CVSS v2 : 6.0
v3 : 7.5
v2 : 6.0
v3 : 3.1

Information

Published : 2018-08-06 14:29

Updated : 2024-11-21 04:00


NVD link : CVE-2018-1551

Mitre link : CVE-2018-1551

CVE.ORG link : CVE-2018-1551


JSON object : View

Products Affected

ibm

  • websphere_mq
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource