CVE-2015-5011: IBM Integration Bus

Low severity, CVSS 3.2. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

Affected products

  • IBM Integration Bus: version 9.0 only; version 9.0.0.1 only; version 9.0.0.2 only; version 9.0.0.3 only
  • IBM WebSphere Message Broker: version 8.0 only; version 8.0.0.1 only; version 8.0.0.2 only; version 8.0.0.3 only; version 8.0.0.4 only; version 8.0.0.5 only

Published 2015-10-26. Last modified 2026-06-17.