First published: Sun Jun 19 2016(Updated: )
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | =8.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7462 is classified as a medium severity vulnerability that allows local users to access sensitive information.
To mitigate CVE-2015-7462, update to a version of IBM WebSphere MQ that is not vulnerable, specifically a version later than 8.0.0.4.
CVE-2015-7462 affects local users on IBM i platforms running IBM WebSphere MQ version 8.0.0.4.
CVE-2015-7462 can expose cleartext certificate-keystore passwords through MQ trace output.
CVE-2015-7462 allows an attacker with administrator privileges to execute the mqcertck program and discover sensitive passwords.