CVE-2015-7462: Infoleak
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7462?
CVE-2015-7462 is classified as a medium severity vulnerability that allows local users to access sensitive information.
How do I fix CVE-2015-7462?
To mitigate CVE-2015-7462, update to a version of IBM WebSphere MQ that is not vulnerable, specifically a version later than 8.0.0.4.
Who is affected by CVE-2015-7462?
CVE-2015-7462 affects local users on IBM i platforms running IBM WebSphere MQ version 8.0.0.4.
What kind of information can be exposed through CVE-2015-7462?
CVE-2015-7462 can expose cleartext certificate-keystore passwords through MQ trace output.
What does CVE-2015-7462 enable an attacker to do?
CVE-2015-7462 allows an attacker with administrator privileges to execute the mqcertck program and discover sensitive passwords.