Vulnerability Name: | CVE-2011-3124 (CCN-68353) | ||||||||
Assigned: | 2011-06-29 | ||||||||
Published: | 2011-06-29 | ||||||||
Updated: | 2012-06-15 | ||||||||
Summary: | IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors. | ||||||||
CVSS v3 Severity: | 8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-3124 Source: CCN Type: SA45036 IBM InfoSphere Information Server File Permissions Privilege Escalation Security Issue Source: SECUNIA Type: Vendor Advisory 45036 Source: AIXAPAR Type: UNKNOWN JR39769 Source: CONFIRM Type: UNKNOWN http://www.ibm.com/support/docview.wss?uid=swg21504279 Source: CONFIRM Type: UNKNOWN http://www.ibm.com/support/docview.wss?uid=swg24030333 Source: CCN Type: OSVDB ID: 74492 IBM InfoSphere Information Server Incorrect File Ownership Local Privilege Escalation Source: BID Type: UNKNOWN 48516 Source: CCN Type: BID-48516 IBM InfoSphere Information Server Multiple Local Privilege Escalation Vulnerabilities Source: XF Type: UNKNOWN ibm-iis-dsengine-priv-escalation(68353) Source: CCN Type: IBM Security Alert A privilege escalation vulnerability on the Engine tier (8.5 & 8.5 Fix Pack 1) can allow the dsadm user to gain root authority. Source: CCN Type: IBM Support and Downloads Download fix for Security Vulnerability: privilege escalation, APAR JR39769 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |