Local Access Bypass in IBM WebSphere MQ
CVE-2015-7473
2.5LOW
Summary
IBM WebSphere MQ prior to version 8.0.0.5 contains a security flaw in the runmqsc utility that permits local users to bypass specific queue-manager command access restrictions. This is achieved by exploiting the permissions associated with the +connect and +dsp authorities, potentially allowing unauthorized command execution within the queue manager environment.
References
CVSS V3.1
Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved