IBM WebSphere MQ 6.0 on OpenVMS, when the default rights of the MQM group are established, does not properly verify User Authorization File (UAF) data, which allows local users to kill listener processes and the command server via a control command.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/46837 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/71336 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1IC78034 | vendor advisory |