CVE-2015-5011

IBM WebSphere Message Broker 8 & Integration Bus 9 - Unauthenticated Command Execution

Title source: llm
STIX 2.1

Description

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21967265
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI28139

Scores

EPSS 0.0033
EPSS Percentile 25.3%

Details

CWE
CWE-77
Status published
Products (10)
ibm/integration_bus 9.0
ibm/integration_bus 9.0.0.1
ibm/integration_bus 9.0.0.2
ibm/integration_bus 9.0.0.3
ibm/websphere_message_broker 8.0
ibm/websphere_message_broker 8.0.0.1
ibm/websphere_message_broker 8.0.0.2
ibm/websphere_message_broker 8.0.0.3
ibm/websphere_message_broker 8.0.0.4
ibm/websphere_message_broker 8.0.0.5
Published Oct 26, 2015
Tracked Since Feb 18, 2026