CVE-2009-0439
Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.37% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere mq
- Source
- cve@mitre.org
References
- http://osvdb.org/52297
- http://secunia.com/advisories/34034
- http://www-01.ibm.com/support/docview.wss?rs=171&uid=swg27006037Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ40824
- http://www.securityfocus.com/bid/33857
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48529
- http://osvdb.org/52297
- http://secunia.com/advisories/34034
- http://www-01.ibm.com/support/docview.wss?rs=171&uid=swg27006037Patch
- http://www-1.ibm.com/support/docview.wss?uid=swg1IZ40824
- http://www.securityfocus.com/bid/33857
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48529
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.