// For flags

CVE-2008-1592

 

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."

MQSeries 5.1 en IBM WebSphere MQ de 5.1 a 5.3.1 en las plataformas HP NonStop y Tandem NSK no requiere que se sea del grupo mqm para la ejecución de tareas administrativas, lo que permite a usuarios locales evitar las restricciones de acceso pervistas a través del programa runmqsc, relacionado con "paneles Pathway".

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-31 CVE Reserved
  • 2008-03-31 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.1
Search vendor "Ibm" for product "Websphere Mq" and version "5.1"
-
Affected
in Hp
Search vendor "Hp"
Nonstop
Search vendor "Hp" for product "Nonstop"
*-
Safe
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.1
Search vendor "Ibm" for product "Websphere Mq" and version "5.1"
-
Affected
in Tandem Computers
Search vendor "Tandem Computers"
Tandem Operating System
Search vendor "Tandem Computers" for product "Tandem Operating System"
nsk
Search vendor "Tandem Computers" for product "Tandem Operating System" and version "nsk"
-
Safe
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.3
Search vendor "Ibm" for product "Websphere Mq" and version "5.3"
-
Affected
in Hp
Search vendor "Hp"
Nonstop
Search vendor "Hp" for product "Nonstop"
*-
Safe
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.3
Search vendor "Ibm" for product "Websphere Mq" and version "5.3"
-
Affected
in Tandem Computers
Search vendor "Tandem Computers"
Tandem Operating System
Search vendor "Tandem Computers" for product "Tandem Operating System"
nsk
Search vendor "Tandem Computers" for product "Tandem Operating System" and version "nsk"
-
Safe
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.3.1
Search vendor "Ibm" for product "Websphere Mq" and version "5.3.1"
-
Affected
in Hp
Search vendor "Hp"
Nonstop
Search vendor "Hp" for product "Nonstop"
*-
Safe
Ibm
Search vendor "Ibm"
Websphere Mq
Search vendor "Ibm" for product "Websphere Mq"
5.3.1
Search vendor "Ibm" for product "Websphere Mq" and version "5.3.1"
-
Affected
in Tandem Computers
Search vendor "Tandem Computers"
Tandem Operating System
Search vendor "Tandem Computers" for product "Tandem Operating System"
nsk
Search vendor "Tandem Computers" for product "Tandem Operating System" and version "nsk"
-
Safe