CVE-2011-1376: Medium severity ibm websphere application server feature pack for web services vulnerability
iscdeploy in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 on the IBM i platform sets weak permissions under systemapps/isclite.ear/ and bin/clientffdc/, which allows local users to read or modify files via standard filesystem operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1376?
CVE-2011-1376 is considered a moderate severity vulnerability due to the potential for local users to access sensitive files.
How do I fix CVE-2011-1376?
To fix CVE-2011-1376, it is recommended to update IBM WebSphere Application Server to the latest patched version that addresses the permissions issue.
Which versions of IBM WebSphere Application Server are affected by CVE-2011-1376?
Versions 6.1 prior to 6.1.0.43, 7.0 prior to 7.0.0.21, and 8.0 prior to 8.0.0.2 are affected by CVE-2011-1376.
Can local users exploit CVE-2011-1376 in my environment?
Yes, local users can exploit CVE-2011-1376 to read or modify files if they have access to the specified directories.
What are the potential consequences of CVE-2011-1376?
The consequences of CVE-2011-1376 include unauthorized access to sensitive information and potential data tampering by local users.