First published: Mon Jun 29 2015(Updated: )
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM DataStage | =8.1 | |
IBM DataStage | =8.5 | |
IBM DataStage | =8.7 | |
IBM DataStage | =9.1 | |
IBM DataStage | =11.3 | |
IBM DataStage | =11.3.1 | |
IBM DataStage | =11.3.1.2 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1900 has a high severity level due to its ability to allow local users to obtain root privileges.
To fix CVE-2015-1900, apply the latest patches and updates from IBM for affected versions of InfoSphere DataStage.
CVE-2015-1900 affects IBM InfoSphere DataStage versions 8.1, 8.5, 8.7, 9.1, 11.3, and 11.3.1.2 on UNIX.
CVE-2015-1900 cannot be exploited remotely as it requires local access to the system.
CVE-2015-1900 enables local users to write to executable files, potentially leading to privilege escalation.