CVE-2015-2012: Infoleak
The MQXR service in WMQ Telemetry in IBM WebSphere MQ 7.1 before 7.1.0.7, 7.5 through 7.5.0.5, and 8.0 before 8.0.0.4 uses world-readable permissions for a cleartext file containing the SSL keystore password, which allows local users to obtain sensitive information by reading this file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2012?
CVE-2015-2012 has a high severity rating due to the potential disclosure of sensitive information.
How do I fix CVE-2015-2012?
To fix CVE-2015-2012, update to IBM WebSphere MQ version 7.1.0.7, 7.5.0.6, or 8.0.0.4 or later.
What software is affected by CVE-2015-2012?
CVE-2015-2012 affects IBM WebSphere MQ versions 7.1, 7.5, and 8.0 prior to specific patch levels.
What vulnerability does CVE-2015-2012 exploit?
CVE-2015-2012 exploits the use of world-readable permissions on a cleartext file containing the SSL keystore password.
Can local users exploit CVE-2015-2012?
Yes, local users can exploit CVE-2015-2012 to read the sensitive information from the vulnerable file.