Local File Permission Weakness in WebSphere MQ by IBM
CVE-2015-2012

4MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
8 February 2016

What is CVE-2015-2012?

The MQXR service within IBM WebSphere MQ has a significant vulnerability related to file permissions. Specifically, older versions of the software may have world-readable permissions on a cleartext file that contains the SSL keystore password. This oversight could permit local users to gain unauthorized access to sensitive information by simply reading the file. Prompt remediation is required to mitigate risks associated with potential data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.