IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2011-11-25 19:57
Updated : 2017-08-16 18:34
NVD link : CVE-2011-1378
Mitre link : CVE-2011-1378
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
hp
- openvms
ibm
- websphere_mq