PT-2017-12981 · Ibm · Ibm Business Process Manager

Publicado

2017-09-25

·

Atualizado

2017-09-28

·

CVE-2017-1346

CVSS v3.1

2.5

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Business Process Manager versions 7.5 through 8.5
Description The issue allows a local user to read files temporarily stored in a folder during offline installs, within a short timespan.
Recommendations For versions 7.5 through 8.5, consider restricting access to the temporary folder used during offline installs to prevent unauthorized reading of files.

Correção

Race Condition

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-1346

Produtos afetados

Ibm Business Process Manager