CVE-2015-1985

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
03/01/2016
Last modified:
12/04/2025

Description

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a stash file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:mq_appliance_m2000:*:*:*:*:*:*:*:* 8.0.0.3 (including)