IBM MQ is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. The issue is described by CVE-2021-38950.
CVEID:CVE-2021-38950
**DESCRIPTION:**IBM MQ on HPE NonStop is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/211404 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
IBM MQ for HPE NonStop | 8.1.0 |
IBM MQ for HPE NonStop | 8.0.4 |
IBM MQ V8.1 for HPE NonStop | 8.1.0.9 | IT38634 | Upgrade to Fixpack 8.1.0.9 |
---|
None