CVE-2016-5879: Input Validation
Published Sep 2, 2016
·Updated
MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.
Affected Software
3 affected components
IBM Mq Appliance Firmware=8.0
IBM MQ Appliance M2000
IBM Mq Appliance M2001
Event History
Sep 2, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5879?
CVE-2016-5879 is considered a high severity vulnerability due to its potential for local users to execute arbitrary shell commands.
2
How do I fix CVE-2016-5879?
To fix CVE-2016-5879, it is recommended to update the IBM MQ Appliance firmware to the latest version provided by IBM.
3
Which IBM MQ versions are affected by CVE-2016-5879?
CVE-2016-5879 affects IBM MQ Appliance firmware version 8.0.
4
What devices are impacted by CVE-2016-5879?
CVE-2016-5879 impacts the IBM MQ Appliance M2000 and M2001 devices.
5
What kind of attack can CVE-2016-5879 enable?
CVE-2016-5879 can enable local users to execute arbitrary shell commands, posing a risk to system integrity.