VulnerabilityModified
CVE-2008-1130
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
MEDIUM 6.6EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a queue manager via a SVRCONN (MQ client) channel.
- CVSS 2.0
- 6.6 MEDIUMAV:L/AC:L/Au:N/C:C/I:C/A:N
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ibm/websphere mq
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29170Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg1IZ01272
- http://www.securityfocus.com/bid/28046
- http://www.securitytracker.com/id?1019527
- http://www.vupen.com/english/advisories/2008/0719
- http://secunia.com/advisories/29170Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?rs=171&uid=swg1IZ01272
- http://www.securityfocus.com/bid/28046
- http://www.securitytracker.com/id?1019527
- http://www.vupen.com/english/advisories/2008/0719
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.