Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7x3-5rwc-88x4

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

EPSS

Процентиль: 32%
0.00124
Низкий

Дефекты

CWE-77

Связанные уязвимости

nvd
больше 10 лет назад

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

EPSS

Процентиль: 32%
0.00124
Низкий

Дефекты

CWE-77