CVE-2019-4078: High severity ibm websphere mq appliance vulnerability
IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute code as an administrator due to incorrect permissions set on MQ installation directories. IBM X-Force ID: 157190.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-4078?
CVE-2019-4078 is a vulnerability in IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 that could allow a local non-privileged user to execute code as an administrator due to incorrect permissions.
What is the severity of CVE-2019-4078?
CVE-2019-4078 has a severity rating of 7.8 out of 10.
How does CVE-2019-4078 affect IBM WebSphere MQ?
CVE-2019-4078 affects IBM WebSphere MQ versions 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1.
How can an attacker exploit CVE-2019-4078?
To exploit CVE-2019-4078, an attacker would need local access to the system and execute code with incorrect permissions.
Is there a fix for CVE-2019-4078?
Yes, IBM has released fixes for CVE-2019-4078. Please refer to the IBM support page for more information.