Vulnerability Bulletins |
IBM Security Bulletin: IBM WebSphere MQ Improper access control for some local MQSC commands (CVE-2015-7473) |
|
| Affected software | IBM |
|
runmqsc allows a user who already has +connect and +dsp authority to a queue manager to perform a small number of commands that would normally require additional privileges. The vulnerability does not affect client MQSC, only locally connected runmqsc.CVE(s): CVE-2015-7473Affected product(s) and affected version(s):The problem affects IBM WebSphere MQ 8.0.0.0 through 8.0.0.4 maintenance levels, previous MQ releases required users to be administrative users to be able to execute the runmqsc More info: https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-websphere-mq-improper-access-control-for-some-local-mqsc-commands-cve-2015-7473/ |
|






