CVE-2012-3311
3.3
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 3.4 / Impact: 4.9
Source: NVD
Description
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.
Affected (51)
Products: Ibm: Websphere Application Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.1.0.0 |
| Running on/with | Platform Versions |
|---|---|
Ibm Z/os | All versions |
Related CWEs
References (8)
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.