Vulnerability Name:

CVE-2011-3123 (CCN-69163)

Assigned:2011-06-29
Published:2011-06-29
Updated:2012-06-15
Summary:IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2011-3123

Source: CCN
Type: SA45036
IBM InfoSphere Information Server File Permissions Privilege Escalation Security Issue

Source: SECUNIA
Type: Vendor Advisory
45036

Source: AIXAPAR
Type: UNKNOWN
JR39769

Source: CONFIRM
Type: UNKNOWN
http://www.ibm.com/support/docview.wss?uid=swg21504279

Source: CONFIRM
Type: UNKNOWN
http://www.ibm.com/support/docview.wss?uid=swg24030333

Source: CCN
Type: OSVDB ID: 73551
IBM InfoSphere Information Server DSEngine File Permissions Local Privilege Escalation

Source: BID
Type: UNKNOWN
48516

Source: CCN
Type: BID-48516
IBM InfoSphere Information Server Multiple Local Privilege Escalation Vulnerabilities

Source: XF
Type: UNKNOWN
infosphere-permissions-priv-escalation(69163)

Source: CCN
Type: IBM Security Alert
A privilege escalation vulnerability on the Engine tier (8.5 & 8.5 Fix Pack 1) can allow the dsadm user to gain root authority.

Source: CCN
Type: IBM Support and Downloads
Download fix for Security Vulnerability: privilege escalation, APAR JR39769

Vulnerable Configuration:Configuration 1:
  • cpe:/a:ibm:infosphere_datastage:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_datastage:8.5.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    ibm infosphere datastage 8.5
    ibm infosphere datastage 8.5.0.1
    ibm infosphere information server 8.5
    ibm infosphere information server 8.5.0.1
    linux linux kernel *
    ibm infosphere information server 8.5
    ibm infosphere information server 8.5.0.1