CVE-2015-5011
IBM WebSphere Message Broker 8 & Integration Bus 9 - Unauthenticated Command Execution
Title source: llmDescription
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21967265
Patch, Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI28139
Scores
EPSS
0.0033
EPSS Percentile
25.3%
Details
CWE
CWE-77
Status
published
Products (10)
ibm/integration_bus
9.0
ibm/integration_bus
9.0.0.1
ibm/integration_bus
9.0.0.2
ibm/integration_bus
9.0.0.3
ibm/websphere_message_broker
8.0
ibm/websphere_message_broker
8.0.0.1
ibm/websphere_message_broker
8.0.0.2
ibm/websphere_message_broker
8.0.0.3
ibm/websphere_message_broker
8.0.0.4
ibm/websphere_message_broker
8.0.0.5
Published
Oct 26, 2015
Tracked Since
Feb 18, 2026