Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The WebSphere MQ XA 5.3 before FP13 and 6.0.x before 6.0.2.1 client for Windows, when running in an MTS or a COM+ environment, grants the PROCESS_DUP_HANDLE privilege to the Everyone group upon connection to a queue manager, which allows local users to duplicate an arbitrary handle and possibly hijack an arbitrary process.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere MQ 权限许可和访问控制漏洞
Vulnerability Description
当在MTS或COM+环境下运行时,Windows WebSphere MQ XA中的客户端,授予与队列服务器相连的每一小组PROCESS_DUP_HANDLE特权,这使得本地用户可以复制任意的句柄以及可能劫持任意进程。
CVSS Information
N/A
Vulnerability Type
N/A