First published: Mon Aug 06 2018(Updated: )
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | >=8.0.0.2<=8.0.0.8 | |
IBM WebSphere MQ | >=9.0.0.0<=9.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1551 is high.
The affected software of CVE-2018-1551 is IBM WebSphere MQ versions 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3.
An attacker can exploit CVE-2018-1551 by creating an invalid user group name, allowing them to have more authority than they should have.
Yes, there are known references for CVE-2018-1551. They can be found at the following links: [http://www.securityfocus.com/bid/105040](http://www.securityfocus.com/bid/105040), [https://exchange.xforce.ibmcloud.com/vulnerabilities/142888](https://exchange.xforce.ibmcloud.com/vulnerabilities/142888), [https://www.ibm.com/support/docview.wss?uid=ibm10716113](https://www.ibm.com/support/docview.wss?uid=ibm10716113).
The CWE ID for CVE-2018-1551 is 732.