CVE-2017-1699: Low severity ibm websphere mq appliance vulnerability
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-1699?
CVE-2017-1699 is a vulnerability in IBM MQ Managed File Transfer Agent 8.0 and 9.0 that sets insecure permissions on certain files it creates.
How can a local attacker exploit CVE-2017-1699?
A local attacker could exploit CVE-2017-1699 to modify or delete data contained in the files with an unknown impact.
What is the severity of CVE-2017-1699?
The severity of CVE-2017-1699 is low with a CVSS score of 3.3.
Which versions of IBM WebSphere MQ are affected by CVE-2017-1699?
IBM WebSphere MQ 8.0, 8.0.0.1, 8.0.0.2, 8.0.0.3, 8.0.0.4, 8.0.0.5, 8.0.0.6, 9.0, 9.0.0.1, 9.0.1, 9.0.2, and 9.0.3 are affected by CVE-2017-1699.
How to fix CVE-2017-1699?
IBM has released security updates for IBM MQ Managed File Transfer Agent 8.0 and 9.0 to address the insecure permissions issue. Apply the latest updates from IBM to fix CVE-2017-1699.