First published: Tue Sep 25 2012(Updated: )
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM z\/os | ||
Ibm Websphere Application Server | =6.1.0 | |
Ibm Websphere Application Server | =6.1.0.0 | |
Ibm Websphere Application Server | =6.1.0.1 | |
Ibm Websphere Application Server | =6.1.0.2 | |
Ibm Websphere Application Server | =6.1.0.3 | |
Ibm Websphere Application Server | =6.1.0.4 | |
Ibm Websphere Application Server | =6.1.0.5 | |
Ibm Websphere Application Server | =6.1.0.7 | |
Ibm Websphere Application Server | =6.1.0.9 | |
Ibm Websphere Application Server | =6.1.0.11 | |
Ibm Websphere Application Server | =6.1.0.12 | |
Ibm Websphere Application Server | =6.1.0.15 | |
Ibm Websphere Application Server | =6.1.0.17 | |
Ibm Websphere Application Server | =6.1.0.19 | |
Ibm Websphere Application Server | =6.1.0.21 | |
Ibm Websphere Application Server | =6.1.0.23 | |
Ibm Websphere Application Server | =6.1.0.25 | |
Ibm Websphere Application Server | =6.1.0.27 | |
Ibm Websphere Application Server | =6.1.0.29 | |
Ibm Websphere Application Server | =6.1.0.31 | |
Ibm Websphere Application Server | =6.1.0.33 | |
Ibm Websphere Application Server | =6.1.0.35 | |
Ibm Websphere Application Server | =6.1.0.37 | |
Ibm Websphere Application Server | =6.1.0.39 | |
Ibm Websphere Application Server | =6.1.0.41 | |
Ibm Websphere Application Server | =6.1.0.43 | |
Ibm Websphere Application Server | =7.0.0.1 | |
Ibm Websphere Application Server | =7.0.0.2 | |
Ibm Websphere Application Server | =7.0.0.3 | |
Ibm Websphere Application Server | =7.0.0.4 | |
Ibm Websphere Application Server | =7.0.0.5 | |
Ibm Websphere Application Server | =7.0.0.6 | |
Ibm Websphere Application Server | =7.0.0.7 | |
Ibm Websphere Application Server | =7.0.0.8 | |
Ibm Websphere Application Server | =7.0.0.9 | |
Ibm Websphere Application Server | =7.0.0.10 | |
Ibm Websphere Application Server | =7.0.0.11 | |
Ibm Websphere Application Server | =7.0.0.13 | |
Ibm Websphere Application Server | =7.0.0.14 | |
Ibm Websphere Application Server | =7.0.0.15 | |
Ibm Websphere Application Server | =7.0.0.16 | |
Ibm Websphere Application Server | =7.0.0.17 | |
Ibm Websphere Application Server | =7.0.0.19 | |
Ibm Websphere Application Server | =7.0.0.21 | |
Ibm Websphere Application Server | =7.0.0.23 | |
Ibm Websphere Application Server | =8.0.0.0 | |
Ibm Websphere Application Server | =8.0.0.1 | |
Ibm Websphere Application Server | =8.0.0.2 | |
Ibm Websphere Application Server | =8.0.0.3 | |
Ibm Websphere Application Server | =8.0.0.4 | |
Ibm Websphere Application Server | =8.5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3311 is classified as a moderate severity vulnerability that could allow local users to bypass security checks.
To mitigate CVE-2012-3311, upgrade IBM WebSphere Application Server to the latest fixed versions according to the vendor's advisories.
CVE-2012-3311 affects IBM WebSphere Application Server versions 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1.
CVE-2012-3311 is a local privilege escalation vulnerability due to improper handling of security checks in specific configurations.
As of the latest updates, there are no publicly disclosed exploits specifically targeting CVE-2012-3311.