IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2011-10-30 12:55
Updated : 2017-08-16 18:30
NVD link : CVE-2009-0905
Mitre link : CVE-2009-0905
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
ibm
- websphere_mq