3.2
CVSSv2

CVE-2015-5011

Published: 26/10/2015 Updated: 27/10/2015
CVSS v2 Base Score: 3.2 | Impact Score: 4.9 | Exploitability Score: 3.1
VMScore: 285
Vector: AV:L/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

IBM WebSphere Message Broker 8 prior to 8.0.0.6 and Integration Bus 9 prior to 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere message broker 8.0

ibm websphere message broker 8.0.0.2

ibm websphere message broker 8.0.0.3

ibm websphere message broker 8.0.0.4

ibm websphere message broker 8.0.0.5

ibm websphere message broker 8.0.0.1

ibm integration bus 9.0

ibm integration bus 9.0.0.2

ibm integration bus 9.0.0.3

ibm integration bus 9.0.0.1