CVE-2015-5011

Published Oct 26, 2015

Last updated 9 years ago

Overview

Description
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
Source
psirt@us.ibm.com
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
3.2
Impact score
4.9
Exploitability score
3.1
Vector string
AV:L/AC:L/Au:S/C:N/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-77

Social media

Hype score
Not currently trending

Configurations