IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Websphere_mq | Ibm | 8.0 (including) | 8.0 (including) |
Websphere_mq | Ibm | 8.0.0.1 (including) | 8.0.0.1 (including) |
Websphere_mq | Ibm | 8.0.0.2 (including) | 8.0.0.2 (including) |
Websphere_mq | Ibm | 8.0.0.3 (including) | 8.0.0.3 (including) |
Websphere_mq | Ibm | 8.0.0.4 (including) | 8.0.0.4 (including) |
Websphere_mq | Ibm | 8.0.0.5 (including) | 8.0.0.5 (including) |
Websphere_mq | Ibm | 8.0.0.6 (including) | 8.0.0.6 (including) |
Websphere_mq | Ibm | 9.0 (including) | 9.0 (including) |
Websphere_mq | Ibm | 9.0.0.1 (including) | 9.0.0.1 (including) |
Websphere_mq | Ibm | 9.0.1 (including) | 9.0.1 (including) |
Websphere_mq | Ibm | 9.0.2 (including) | 9.0.2 (including) |
Websphere_mq | Ibm | 9.0.3 (including) | 9.0.3 (including) |