CVE-2012-3317
6.9
Vector
AV:L/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 3.4 / Impact: 10.0
Source: NVD
Description
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.
Affected (18)
Products: Ibm: Websphere Message Broker
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.1.0.10 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0.0.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0.0.1 |
Related CWEs
References (6)
Source: psirt@us.ibm.com
Source: psirt@us.ibm.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.