CVE-2009-0905: Input Validation
Published Oct 30, 2011
·Updated
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
Affected Software
14 affected components
IBM WebSphere MQ=6.0
IBM WebSphere MQ=6.0.1.0
IBM WebSphere MQ=6.0.1.1
IBM WebSphere MQ=6.0.2.0
IBM WebSphere MQ=6.0.2.1
IBM WebSphere MQ=6.0.2.2
IBM WebSphere MQ=6.0.2.3
IBM WebSphere MQ=6.0.2.4
IBM WebSphere MQ=6.0.2.5
IBM WebSphere MQ=6.0.2.6
IBM WebSphere MQ=6.0.2.7
IBM WebSphere MQ=7.0
IBM WebSphere MQ=7.0.0.1
IBM WebSphere MQ=7.0.0.2
Event History
Oct 30, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-0905?
CVE-2009-0905 is classified as a moderate severity vulnerability due to the potential privilege escalation it allows for local users.
2
How do I fix CVE-2009-0905?
To fix CVE-2009-0905, update IBM WebSphere MQ to version 6.0.2.8 or later or 7.0.1.0 or later.
3
What versions of IBM WebSphere MQ are affected by CVE-2009-0905?
CVE-2009-0905 affects IBM WebSphere MQ versions 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0.
4
Can CVE-2009-0905 be exploited remotely?
CVE-2009-0905 is a local privilege escalation vulnerability, meaning it cannot be exploited remotely.
5
What impact does CVE-2009-0905 have on affected systems?
CVE-2009-0905 allows local users to gain elevated privileges through improperly handled long group names.