CVE-2009-0439: High severity IBM WebSphere MQ vulnerability
Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0439?
CVE-2009-0439 is considered a moderate severity vulnerability that allows local users to gain privileges.
How do I fix CVE-2009-0439?
To fix CVE-2009-0439, update IBM WebSphere MQ to version 6.0.2.6 or later, or 7.0.0.2 or later.
Which versions of IBM WebSphere MQ are affected by CVE-2009-0439?
CVE-2009-0439 affects IBM WebSphere MQ versions 5.3, 6.0 prior to 6.0.2.6, and 7.0 prior to 7.0.0.2.
Who can exploit CVE-2009-0439?
CVE-2009-0439 can be exploited by local users who have access to the affected IBM WebSphere MQ systems.
What actions can be taken to mitigate CVE-2009-0439?
Mitigation for CVE-2009-0439 includes limiting local user access and ensuring systems are updated to versions that include the vulnerability fix.