CVE-2016-0375

HIGH

IBM MessageSight <2.0.0.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain administrator privileges for executing arbitrary commands via unspecified vectors.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21985064
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT15743
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT15674

Scores

CVSS v3 8.8
EPSS 0.0227
EPSS Percentile 81.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (8)
ibm/messagesight 1.1.0.0
ibm/messagesight 1.1.0.1
ibm/messagesight 1.2
ibm/messagesight 1.2.0.0
ibm/messagesight 1.2.0.1
ibm/messagesight 1.2.0.2
ibm/messagesight 1.2.0.3
ibm/messagesight 2.0.0.0
Published Jul 01, 2016
Tracked Since Feb 18, 2026