CVE-2012-2206
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser…
Does this matter?
Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.
Description
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
- EPSS
- 2.01% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/websphere mq
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC82761
- http://www.exploit-db.com/exploits/20478/Exploit
- http://www.ibm.com/support/docview.wss?uid=swg21607481Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77095
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC82761
- http://www.exploit-db.com/exploits/20478/Exploit
- http://www.ibm.com/support/docview.wss?uid=swg21607481Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77095
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.