CVE-2015-5011: IBM Integration Bus
Low severity, CVSS 3.2. EPSS: 0.3% chance of exploitation in the next 30 days.
IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.
Affected products
- IBM Integration Bus: version 9.0 only; version 9.0.0.1 only; version 9.0.0.2 only; version 9.0.0.3 only
- IBM WebSphere Message Broker: version 8.0 only; version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.0.0.4 only; version 8.0.0.5 only
Published 2015-10-26. Last modified 2026-06-17.