CVE Vulnerabilities

CVE-2012-2206

Published: Aug 17, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

Affected Software

Name Vendor Start Version End Version
Websphere_mq Ibm 7.0 (including) 7.0 (including)
Websphere_mq Ibm 7.0.0.1 (including) 7.0.0.1 (including)
Websphere_mq Ibm 7.0.1.0 (including) 7.0.1.0 (including)
Websphere_mq Ibm 7.0.2.0 (including) 7.0.2.0 (including)
Websphere_mq Ibm 7.0.2.2 (including) 7.0.2.2 (including)
Websphere_mq Ibm 7.0.4 (including) 7.0.4 (including)
Websphere_mq Ibm 7.0.4.0 (including) 7.0.4.0 (including)

References