CVE-2012-2206

low
Published 2012-08-17 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21607481

Application impact

VendorProductVersionsFixed
ibmwebsphere_mq7.0
ibmwebsphere_mq7.0.0.1
ibmwebsphere_mq7.0.1.0
ibmwebsphere_mq7.0.2.0
ibmwebsphere_mq7.0.2.2
ibmwebsphere_mq7.0.4
ibmwebsphere_mq7.0.4.0

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.