CVE-2016-6089: Medium severity ibm websphere mq appliance vulnerability
Published Jun 7, 2017
·Updated
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
Affected Software
2 affected components
IBM WebSphere MQ=9.0.0.0
IBM WebSphere MQ=9.0.1
Remediation
Patch Available
Event History
Jun 7, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2016-6089?
CVE-2016-6089 is considered a medium severity vulnerability due to improper access controls in IBM WebSphere MQ.
2
How do I fix CVE-2016-6089?
To fix CVE-2016-6089, ensure to apply the latest security patches provided by IBM for the affected versions of WebSphere MQ.
3
Which versions of WebSphere MQ are affected by CVE-2016-6089?
CVE-2016-6089 affects IBM WebSphere MQ versions 9.0.0.1 and 9.0.2.
4
What type of issues does CVE-2016-6089 cause?
CVE-2016-6089 allows local users to write to or delete files in directories they shouldn't have access to, violating access controls.
5
Is there a workaround for CVE-2016-6089?
There are no official workarounds for CVE-2016-6089, so updating to a patched version is recommended.