SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2206

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser…

LOW 3.5EPSS 2.01%

Does this matter?

Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.

Description

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS
2.01% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
ibm/websphere mq
Source
psirt@us.ibm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.