VulnerabilityModified
CVE-2013-3028
Multiple buffer overflows in mqm programs in IBM WebSphere MQ 7.0.x before 7.0.1.11, 7.1.x before 7.1.0.3, and 7.5.x before 7.5.0.2 on non-Windows platforms allow local users to gain privileges via unspecified vectors.
MEDIUM 4.6EPSS 0.37%
Does this matter?
Lower severity and a low EPSS score (0.37%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple buffer overflows in mqm programs in IBM WebSphere MQ 7.0.x before 7.0.1.11, 7.1.x before 7.1.0.3, and 7.5.x before 7.5.0.2 on non-Windows platforms allow local users to gain privileges via unspecified vectors.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/websphere mq
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV43368
- http://www-01.ibm.com/support/docview.wss?uid=swg21639001Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84564
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV43368
- http://www-01.ibm.com/support/docview.wss?uid=swg21639001Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84564
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.