Page 3 of 18 results (0.018 seconds)

CVSS: 4.3EPSS: 0%CPEs: 19EXPL: 0

IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate. IBM WebSphere MQ v6.x anterior a v6.0.2.10 y v7.x anterior a v7.0.1.3, permite a atacantes remotos suplantar certificados autenticados X.509, y enviar y recibir mensajes del canal a través de un valor manipulado de un Subject Distinguished Name (DN). • http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707 http://www-01.ibm.com/support/docview.wss?uid=swg27014224 https://exchange.xforce.ibmcloud.com/vulnerabilities/60018 •

CVSS: 8.8EPSS: 0%CPEs: 17EXPL: 0

IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue. IBM WebSphere MQ v6.x desde v6.0.2.7, v7.0.0.0, v7.0.0.1, v7.0.0.2, y v7.0.1.0, cuando "read ahead" o "asynchronous message consumption" esta activado, permite a atacantes remotos obtener un impacto desconocido a traves de vectores desconocidos, relacionado con la sobrescritura de memoria. • http://secunia.com/advisories/36647 http://www-01.ibm.com/support/docview.wss?uid=swg24024153 http://www-1.ibm.com/support/docview.wss?uid=swg1IZ56259 http://www.securityfocus.com/bid/36310 http://www.vupen.com/english/advisories/2009/2578 •

CVSS: 10.0EPSS: 15%CPEs: 14EXPL: 0

Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request. Desbordamiento de búfer en el gestor de cola en IBM WebSphere MQ v6.x anterior a v6.0.2.7 y v7.x anterior a v7.0.1.0, permite a atacantes remotos ejecutar código de su elección a través de una petición manipulada. • http://secunia.com/advisories/35303 http://securitytracker.com/id?1022311 http://www-01.ibm.com/support/docview.wss?uid=swg21386826 http://www-1.ibm.com/support/docview.wss?uid=swg1IZ50784 http://www.securityfocus.com/bid/35170 http://www.vupen.com/english/advisories/2009/1463 https://exchange.xforce.ibmcloud.com/vulnerabilities/50641 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 7.2EPSS: 0%CPEs: 13EXPL: 0

Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain privileges via vectors related to the (1) setmqaut, (2) dmpmqaut, and (3) dspmqaut authorization commands. Vulnerabilidad no especificada en el gestor de cola de IBM WebSphere MQ (WMQ) v5.3, v6.0 anterior a v6.0.2.6 y v7.0 anterior a v7.0.0.2; permite a usuarios locales obtener privilegios a través de vectores relacionados con los comandos de autorización (1) setmqaut, (2) dmpmqaut y (3) dspmqaut. • http://osvdb.org/52297 http://secunia.com/advisories/34034 http://www-01.ibm.com/support/docview.wss?rs=171&uid=swg27006037 http://www-1.ibm.com/support/docview.wss?uid=swg1IZ40824 http://www.securityfocus.com/bid/33857 https://exchange.xforce.ibmcloud.com/vulnerabilities/48529 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.6EPSS: 0%CPEs: 5EXPL: 0

MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels." MQSeries 5.1 en IBM WebSphere MQ de 5.1 a 5.3.1 en las plataformas HP NonStop y Tandem NSK no requiere que se sea del grupo mqm para la ejecución de tareas administrativas, lo que permite a usuarios locales evitar las restricciones de acceso pervistas a través del programa runmqsc, relacionado con "paneles Pathway". • http://secunia.com/advisories/29360 http://securitytracker.com/id?1019610 http://www-1.ibm.com/support/docview.wss?uid=swg21297035 http://www.securityfocus.com/bid/28235 http://www.vupen.com/english/advisories/2008/0869 • CWE-264: Permissions, Privileges, and Access Controls •