CVE-2015-1985

MEDIUM

IBM MQ Appliance M2000 < 8.0.0.3 - Improper Access Control

Title source: rule

Description

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

Scores

CVSS v3 5.6
EPSS 0.0004
EPSS Percentile 12.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-284
Status draft

Affected Products (1)

ibm/mq_appliance_m2000 < 8.0.0.3

Timeline

Published Jan 03, 2016
Tracked Since Feb 18, 2026