vendor:
WebSphereMQ File Transfer Edition
by:
Nir Valtman
9,8
CVSS
CRITICAL
Privilege Escalation
264
CWE
Product Name: WebSphereMQ File Transfer Edition
Affected Version From: 7.0.4 and all previous versions
Affected Version To: 7.0.4 and all previous versions
Patch Exists: YES
Related CWE: CVE-2016-5408
CPE: a:ibm:websphere_mq_file_transfer_edition
Metasploit:
https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2016-5408/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2016-5408/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2016-5408/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2016-5408/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2016-5408/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: All
2016
Privilege Escalation in WebSphereMQ File Transfer Edition
Malicious user is able to access other user's files and filespaces. The attack can be executed by sending a GET request to the URL /transfer/?start=0&count=10&metadata=fteSamplesUser=user1. The malicious user should know the file name and the related ID before executing the attack. The malicious user can access the URL /filespace/user1/414d512057514d542020202020202020eb3bfc4f2030df02/changedthisfilename.txt using a GET request.
Mitigation:
Ensure that the WebSphereMQ File Transfer Edition is up to date and all users have the appropriate permissions.