First published: Wed Aug 10 2011(Updated: )
IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataStage | =8.5 | |
IBM DataStage | =8.5.0.1 | |
IBM InfoSphere Information Server | =8.5 | |
IBM InfoSphere Information Server | =8.5.0.1 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3124 is considered a medium severity vulnerability due to its potential to allow local users to gain elevated privileges.
CVE-2011-3124 affects user installations of IBM InfoSphere Information Server and IBM InfoSphere DataStage versions 8.5 and 8.5.0.1 on Unix and Linux systems.
To fix CVE-2011-3124, update IBM InfoSphere Information Server and IBM InfoSphere DataStage to the latest patched versions provided by IBM.
The risks associated with CVE-2011-3124 include unauthorized privilege escalation, which can lead to potential data breaches.
CVE-2011-3124 is caused by improper file ownership settings within IBM InfoSphere's software that can inadvertently grant local users elevated permissions.