CVE-2012-0204: Critical severity ibm infosphere information server vulnerability
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0204?
CVE-2012-0204 is classified as a medium severity vulnerability.
How do I fix CVE-2012-0204?
To fix CVE-2012-0204, upgrade to the patched versions of IBM InfoSphere Import Export Manager and Information Server as provided by IBM.
What causes CVE-2012-0204?
CVE-2012-0204 is caused by an untrusted search path vulnerability allowing privilege escalation via a Trojan horse DLL.
Which versions are affected by CVE-2012-0204?
CVE-2012-0204 affects IBM InfoSphere Import Export Manager versions 8.1 through 9.1 prior to FP3, among others.
Who is impacted by CVE-2012-0204?
Local users of the affected versions of IBM InfoSphere Import Export Manager and Information Server may be impacted by CVE-2012-0204.