VulnerabilityModified
CVE-2011-1378
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
LOW 1.9EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
- CVSS 2.0
- 1.9 LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere mq
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/46837Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71336
- http://secunia.com/advisories/46837Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71336
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.