Vulnerability Bulletins

IBM Security Bulletin: IBM WebSphere MQ Improper access control for some display commands in local runmqsc (CVE-2016-0259)

   
Affected software IBM
 
Various display commands via local runmqsc return data for non-privileged users where they lack appropriate +dsp authority. The problem does not affect remotely connected runmqsc.CVE(s): CVE-2016-0259Affected product(s) and affected version(s):IBM WebSphere MQ 8.0.0.0 through 8.0.0.4 maintenance levelsRefer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=swg21984561X-Force Database:

More info:

https://www.ibm.com/blogs/psirt/ibm-security-bulletin-ibm-websphere-mq-improper-access-control-for-some-display-commands-in-local-runmqsc-cve-2016-0259/