Vulnerability CVE-2017-1382


Published: 2017-07-24   Modified: 2017-07-25

Description:
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.

Type:

CWE-276

(Incorrect Default Permissions)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.6/10
4.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
IBM -> Websphere application server 

 References:
http://www.ibm.com/support/docview.wss?uid=swg22004785
http://www.securityfocus.com/bid/99960
http://www.securitytracker.com/id/1038977
https://exchange.xforce.ibmcloud.com/vulnerabilities/127153

Copyright 2024, cxsecurity.com

 

Back to Top