CVE Vulnerabilities

CVE-2012-2206

Published: Aug 17, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

Affected Software

NameVendorStart VersionEnd Version
Websphere_mqIbm7.0 (including)7.0 (including)
Websphere_mqIbm7.0.0.1 (including)7.0.0.1 (including)
Websphere_mqIbm7.0.1.0 (including)7.0.1.0 (including)
Websphere_mqIbm7.0.2.0 (including)7.0.2.0 (including)
Websphere_mqIbm7.0.2.2 (including)7.0.2.2 (including)
Websphere_mqIbm7.0.4 (including)7.0.4 (including)
Websphere_mqIbm7.0.4.0 (including)7.0.4.0 (including)

References