CVE-2015-2012
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file.
- CVSS 3.0
- 4.0 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.35% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-255
- Affected
- ibm/websphere mq
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT09866
- http://www-01.ibm.com/support/docview.wss?uid=swg21968399Vendor Advisory
- http://www.securitytracker.com/id/1034943
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT09866
- http://www-01.ibm.com/support/docview.wss?uid=swg21968399Vendor Advisory
- http://www.securitytracker.com/id/1034943
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.