CVE-2018-1551
Last modified
CVE-2018-1551 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.. EPSS estimates a 1.14% chance of exploitation in the next 30 days.
Description
IBM WebSphere MQ 8.0.0.2 through 8.0.0.8 and 9.0.0.0 through 9.0.0.3 could allow users to have more authority than they should have if an MQ administrator creates an invalid user group name. IBM X-Force ID: 142888.
Metrics
CVSS:3.0/A:N/AC:H/AV:N/C:N/I:L/PR:L/S:U/UI:N/E:U/RC:C/RL:O
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Mq | >= 8.0.0.2, <= 8.0.0.8 |
| Ibm | Websphere Mq | >= 9.0.0.0, <= 9.0.0.3 |
References
- http://www.securityfocus.com/bid/105040Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/142888VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10716113Vendor Advisory
- http://www.securityfocus.com/bid/105040Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/142888VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10716113Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1551?
How severe is CVE-2018-1551?
How do I fix CVE-2018-1551?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-15503The unpack implementation in Swoole version 4.0.4 lacks corr…
- CVE-2018-15504An issue was discovered in Embedthis GoAhead before 4.0.1 an…7.5
- CVE-2018-15505An issue was discovered in Embedthis GoAhead before 4.0.1 an…7.5
- CVE-2018-15506In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP…
- CVE-2018-15508Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Contro…
- CVE-2018-15509Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Contro…
- CVE-2018-15510Cross-site scripting (XSS) vulnerability in the 'Certificate…
- CVE-2018-15511Cross-site scripting (XSS) vulnerability in the 'Notificatio…
- CVE-2018-15512Cross-site scripting (XSS) vulnerability in the 'Authorisati…
- CVE-2018-15513Log viewer in totemomail 6.0.0 build 570 allows access to se…
- CVE-2018-15514HandleRequestAsync in Docker for Windows before 18.06.0-ce-r…
- CVE-2018-15515The CaptivelPortal service on D-Link Central WiFiManager CWM…
Are you affected by CVE-2018-1551?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
