PT-2012-1512 · Ibm · Ibm Websphere Application Server

Publicado

2012-01-19

·

Atualizado

2017-08-17

·

CVE-2011-1376

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM WebSphere Application Server (WAS) versions 6.1 before 6.1.0.43 IBM WebSphere Application Server (WAS) versions 7.0 before 7.0.0.21 IBM WebSphere Application Server (WAS) versions 8.0 before 8.0.0.2
Description The issue allows local users to read or modify files via standard filesystem operations due to weak permissions set by iscdeploy under systemapps/isclite.ear/ and bin/client ffdc/.
Recommendations For IBM WebSphere Application Server (WAS) versions 6.1 before 6.1.0.43, update to version 6.1.0.43 or later. For IBM WebSphere Application Server (WAS) versions 7.0 before 7.0.0.21, update to version 7.0.0.21 or later. For IBM WebSphere Application Server (WAS) versions 8.0 before 8.0.0.2, update to version 8.0.0.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1376

Produtos afetados

Ibm Websphere Application Server