First published: Thu Jan 31 2013(Updated: )
The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataStage | ||
IBM InfoSphere Information Server | =8.1 | |
IBM InfoSphere Information Server | =8.5 | |
IBM InfoSphere Information Server | =8.5.0.1 | |
IBM InfoSphere Information Server | =8.5.0.2 | |
IBM InfoSphere Information Server | =8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0701 is classified as a medium severity vulnerability due to its potential to allow unauthorized privilege escalation.
To fix CVE-2012-0701, upgrade to IBM InfoSphere DataStage versions 8.1 FP3, 8.5 or later, or 8.7.
CVE-2012-0701 affects IBM InfoSphere DataStage 8.1, 8.5 before FP3, and 8.7.
Yes, CVE-2012-0701 can be exploited by remote authenticated users, which unfortunately includes insiders.
CVE-2012-0701 is an access control vulnerability that relies on client-side controls.