cbcvebase.
CVE-2015-5011
published 2015-10-26

CVE-2015-5011: IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW…

PriorityP49low3.2CVSS 2.0
AVLACLAuSCNIPAP
EPSS
0.33%
25.5th percentile
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

Affected

10 ranges
VendorProductVersion rangeFixed in
ibmintegration_bus
ibmintegration_bus
ibmintegration_bus
ibmintegration_bus
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.