CVE-2018-1792Code Injection in IBM Websphere MQ

CWE-94Code Injection4 documents4 sources
Severity
7.8HIGHNVD
CNA8.8
EPSS
0.3%
top 47.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateMay 13

Description

IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDibm/websphere_mq8.0.0.08.0.0.10+3
CVEListV5ibm/mq24 versions+23

🔴Vulnerability Details

2
GHSA
GHSA-925c-69p2-m4hj: IBM WebSphere MQ 82022-05-13
CVEList
CVE-2018-1792: IBM WebSphere MQ 82018-11-13

💬Community

1
Bugzilla
CVE-2018-20187 botan: Side channel possible during ECC generation2019-01-09
CVE-2018-1792 — Code Injection in IBM Websphere MQ | cvebase