First published: Mon Mar 31 2008(Updated: )
MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HP NonStop | ||
Tandem Computers Tandem Operating System | =nsk | |
IBM WebSphere MQ | =5.1 | |
IBM WebSphere MQ | =5.3 | |
IBM WebSphere MQ | =5.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1592 is considered to be high due to its potential for unauthorized access to administrative tasks.
To fix CVE-2008-1592, ensure that the mqm group membership is required for executing administrative tasks and apply the appropriate patches or updates provided by IBM.
CVE-2008-1592 affects IBM WebSphere MQ versions 5.1, 5.3, and 5.3.1.
CVE-2008-1592 impacts IBM WebSphere MQ running on HP NonStop and Tandem NSK platforms.
Yes, local users can exploit CVE-2008-1592 to bypass intended access restrictions via the runmqsc program.