Description
IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
References (3)
Core 3
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46837
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71336
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034
Scores
EPSS
0.0028
EPSS Percentile
20.0%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/websphere_mq
6.0
Published
Nov 26, 2011
Tracked Since
Feb 18, 2026