First published: Thu Jan 04 2018(Updated: )
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | =8.0 | |
IBM WebSphere MQ | =8.0.0.1 | |
IBM WebSphere MQ | =8.0.0.2 | |
IBM WebSphere MQ | =8.0.0.3 | |
IBM WebSphere MQ | =8.0.0.4 | |
IBM WebSphere MQ | =8.0.0.5 | |
IBM WebSphere MQ | =8.0.0.6 | |
IBM WebSphere MQ | =9.0 | |
IBM WebSphere MQ | =9.0.0.1 | |
IBM WebSphere MQ | =9.0.1 | |
IBM WebSphere MQ | =9.0.2 | |
IBM WebSphere MQ | =9.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1699 is a vulnerability in IBM MQ Managed File Transfer Agent 8.0 and 9.0 that sets insecure permissions on certain files it creates.
A local attacker could exploit CVE-2017-1699 to modify or delete data contained in the files with an unknown impact.
The severity of CVE-2017-1699 is low with a CVSS score of 3.3.
IBM WebSphere MQ 8.0, 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.4, 8.0.0.5, 8.0.0.6, 9.0, 9.0.0.1, 9.0.1, 9.0.2, and 9.0.3 are affected by CVE-2017-1699.
IBM has released security updates for IBM MQ Managed File Transfer Agent 8.0 and 9.0 to address the insecure permissions issue. Apply the latest updates from IBM to fix CVE-2017-1699.