First published: Wed Jun 07 2017(Updated: )
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | =9.0.0.0 | |
IBM WebSphere MQ | =9.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6089 is considered a medium severity vulnerability due to improper access controls in IBM WebSphere MQ.
To fix CVE-2016-6089, ensure to apply the latest security patches provided by IBM for the affected versions of WebSphere MQ.
CVE-2016-6089 affects IBM WebSphere MQ versions 9.0.0.1 and 9.0.2.
CVE-2016-6089 allows local users to write to or delete files in directories they shouldn't have access to, violating access controls.
There are no official workarounds for CVE-2016-6089, so updating to a patched version is recommended.