← Back

CVE-2011-1376

nvd nist
Published: Jan 19, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.6
Vector
AV:L/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 3.9 / Impact: 6.4
Source: NVD

Description

iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/client_ffdc/, which allows local users to read or modify files via standard filesystem operations.

Affected (35)

1 product
Websphere Application Server
Configuration A
22 vulnerable
Configuration B
11 vulnerable
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 8.0.0.1
Version 8.0

Related CWEs

References (8)

Timeline

No history available yet.