CVE-2015-5011: Command Injection
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5011?
CVE-2015-5011 has a medium severity rating due to the potential for unauthorized access to start or stop critical message flows.
How do I fix CVE-2015-5011?
To fix CVE-2015-5011, upgrade IBM WebSphere Message Broker to version 8.0.0.6 or later, or IBM Integration Bus to version 9.0.0.4 or later.
What systems are affected by CVE-2015-5011?
CVE-2015-5011 affects IBM WebSphere Message Broker versions 8.0.0.1 to 8.0.0.5 and IBM Integration Bus versions 9.0.0.1 to 9.0.0.3.
What can an attacker do with CVE-2015-5011?
An attacker exploiting CVE-2015-5011 can issue MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands to control message flows without authorization.
Is there a workaround for CVE-2015-5011?
There are no official workarounds for CVE-2015-5011, so it is strongly advised to apply the necessary patches.