CVE-2014-4793

IBM WebSphere MQ <8.0.0.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21685526
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95208

Scores

EPSS 0.0107
EPSS Percentile 61.5%

Details

CWE
CWE-264
Status published
Products (1)
ibm/websphere_mq 8.0.0.0
Published Oct 02, 2014
Tracked Since Feb 18, 2026