CVE-2012-2206: Low severity ibm websphere mq appliance vulnerability
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2206?
CVE-2012-2206 has been classified as a medium-severity vulnerability.
How do I fix CVE-2012-2206?
To fix CVE-2012-2206, upgrade to a version of IBM WebSphere MQ File Transfer Edition later than 7.0.4.
Who is affected by CVE-2012-2206?
CVE-2012-2206 affects remote authenticated users of IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier.
What type of vulnerability is CVE-2012-2206?
CVE-2012-2206 is an information disclosure vulnerability that allows unauthorized file access through manipulated URIs.
What products are vulnerable in CVE-2012-2206?
The vulnerable products include IBM WebSphere MQ File Transfer Editions 7.0 through 7.0.4.