{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"IBM WebSphere MQ 7.0.","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}},{"description":"IBM WebSphere MQ 5.3 ;","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}},{"description":"IBM WebSphere MQ 6.0.x ;","product":{"name":"WebSphere","vendor":{"name":"IBM","scada":false}}}],"affected_systems_content":null,"content":"## Description\n\nUne vuln\u00e9rabilit\u00e9 affectant les commandes setmqaut, dmpmqaut et dspmqaut\npermet \u00e0 une personne malintentionn\u00e9e, pr\u00e9alablement authentifi\u00e9e,\nd'\u00e9lever ses privil\u00e8ges sur le syst\u00e8me. Cette vuln\u00e9rabilit\u00e9 n'affecte\nque les syst\u00e8mes UNIX.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2009-0439","url":"https://www.cve.org/CVERecord?id=CVE-2009-0439"}],"links":[],"reference":"CERTA-2009-AVI-077","revisions":[{"description":"version initiale.","revision_date":"2009-02-25T00:00:00.000000"}],"risks":[{"description":"\u00c9l\u00e9vation de privil\u00e8ges"}],"summary":"Une vuln\u00e9rabilit\u00e9 affectant IBM WebSphere MQ permet \u00e0 une personne\nmalintentionn\u00e9e d'\u00e9lever ses privil\u00e8ges sur le syst\u00e8me.\n","title":"Vuln\u00e9rabilit\u00e9 dans IBM WebSphere MQ","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 IBM swg21376107 du 23 f\u00e9vrier 2009","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21376107"}]}
