CVE-2012-3317
Last modified
CVE-2012-3317 is a vulnerability of currently unknown severity. IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Websphere Message Broker | 6.1 |
| Ibm | Websphere Message Broker | 6.1.0.1 |
| Ibm | Websphere Message Broker | 6.1.0.2 |
| Ibm | Websphere Message Broker | 6.1.0.3 |
| Ibm | Websphere Message Broker | 6.1.0.4 |
| Ibm | Websphere Message Broker | 6.1.0.5 |
| Ibm | Websphere Message Broker | 6.1.0.6 |
| Ibm | Websphere Message Broker | 6.1.0.7 |
| Ibm | Websphere Message Broker | 6.1.0.8 |
| Ibm | Websphere Message Broker | 6.1.0.9 |
| Ibm | Websphere Message Broker | 6.1.0.10 |
| Ibm | Websphere Message Broker | 7.0. |
| Ibm | Websphere Message Broker | 7.0.0.1 |
| Ibm | Websphere Message Broker | 7.0.0.2 |
| Ibm | Websphere Message Broker | 7.0.0.3 |
| Ibm | Websphere Message Broker | 7.0.0.4 |
| Ibm | Websphere Message Broker | 8.0 |
| Ibm | Websphere Message Broker | 8.0.0.1 |
References
- http://www.ibm.com/support/docview.wss?uid=swg21611401Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg21611401Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3317?
How severe is CVE-2012-3317?
How do I fix CVE-2012-3317?
Are you affected by CVE-2012-3317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
