IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2011-10-30 19:55
Updated : 2024-02-04 17:54
NVD link : CVE-2009-0905
Mitre link : CVE-2009-0905
CVE.ORG link : CVE-2009-0905
JSON object : View
Products Affected
ibm
- websphere_mq
CWE
CWE-20
Improper Input Validation