V-224361 | High | Websphere MQ switch profiles must be properly defined to the MQADMIN class.
| WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224354 | High | WebSphere MQ channel security must be implemented in accordance with security requirements. | WebSphere MQ Channel security can be configured to provide authentication, message privacy, and message integrity between queue managers. Secure Sockets Layer (SSL) uses encryption techniques,... |
V-224362 | Medium | WebSphere MQ MQCONN Class resources must be protected in accordance with security. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224363 | Medium | WebSphere MQ dead letter and alias dead letter queues are not properly defined. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224360 | Medium | WebSphere MQ resource classes are not properly activated. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224366 | Medium | WebSphere MQ Namelist resources are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224359 | Medium | WebSphere MQ all update and alter access to MQSeries/WebSphere MQ product and system data sets are not properly restricted. | MVS data sets provide the configuration, operational, and executable properties of WebSphere MQ. Some data sets are responsible for the security implementation of WebSphere MQ. Failure to properly... |
V-224364 | Medium | WebSphere MQ queue resource defined to the MQQUEUE resource class are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224358 | Medium | WebSphere MQ started tasks are not defined in accordance with the proper security requirements. | Started tasks are used to execute WebSphere MQ queue manager services. Improperly defined WebSphere MQ started tasks may result in inappropriate access to application resources and the loss of... |
V-224357 | Medium | User timeout parameter values for WebSphere MQ queue managers are not specified in accordance with security requirements.
| Users signed on to a WebSphere MQ queue manager could leave their terminals unattended for long periods of time. This may allow unauthorized individuals to gain access to WebSphere MQ resources... |
V-224356 | Medium | Production WebSphere MQ Remotes must utilize Certified Name Filters (CNF). | IBM WebSphere MQ can use a user ID associated with an ACP certificate as a channel user ID. When an entity at one end of an SSL channel receives a certificate from a remote connection, the entity... |
V-224355 | Medium | WebSphere MQ channel security is not implemented in accordance with security requirements. | WebSphere MQ channel security can be configured to provide authentication, message privacy, and message integrity between queue managers. WebSphere MQ channels use SSL encryption techniques,... |
V-224367 | Medium | WebSphere MQ alternate user resources defined to MQADMIN resource class are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224368 | Medium | WebSphere MQ context resources defined to the MQADMIN resource class are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224369 | Medium | WebSphere MQ command resources defined to MQCMDS resource class are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224365 | Medium | WebSphere MQ Process resources are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |
V-224370 | Medium | WebSphere MQ RESLEVEL resources in the MQADMIN resource class are not protected in accordance with security requirements. | WebSphere MQ resources allow for the control of administrator functions, connections, commands, queues, processes, and namelists. Some resources provide the ability to disable or bypass security... |