First published: Mon Mar 11 2019(Updated: )
IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges. This is due to an incomplete fix for CVE-2018-1792. IBM X-ForceID: 154887.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ | >=8.0.0.0<=8.0.0.10 | |
IBM WebSphere MQ | >=9.0.0.0<=9.0.0.5 | |
IBM WebSphere MQ | >=9.1.0.0<=9.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1998 is a vulnerability in IBM WebSphere MQ that allows a local user to inject code and execute it with root privileges.
CVE-2018-1998 has a severity score of 7.8 out of 10.
IBM WebSphere MQ versions 8.0.0.0 to 8.0.0.10, 9.0.0.0 to 9.0.0.5, and 9.1.0.0 to 9.1.0.1 are affected by CVE-2018-1998.
The incomplete fix related to CVE-2018-1998 is CVE-2018-1792.
To fix CVE-2018-1998, upgrade IBM WebSphere MQ to a version that includes a complete fix for the vulnerability.