CVE-2015-1985

MEDIUM

IBM MQ Appliance M2000 < 8.0.0.4 - Unauthenticated Private Key Exposure via Stash File

Title source: llm
STIX 2.1

Description

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21971445

Scores

CVSS v3 5.6
EPSS 0.0023
EPSS Percentile 14.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-284
Status published
Products (1)
ibm/mq_appliance_m2000 < 8.0.0.3
Published Jan 03, 2016
Tracked Since Feb 18, 2026