CVE-2016-0394: Low severity IBM Integration Bus vulnerability
Published Feb 1, 2017
·Updated
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
Affected Software
10 affected components
IBM Integration Bus=9.0
IBM Integration Bus=9.0.0.1
IBM Integration Bus=9.0.0.2
IBM Integration Bus=10.0
IBM WebSphere Message Broker=8.0
IBM WebSphere Message Broker=8.0.0.1
IBM WebSphere Message Broker=8.0.0.2
IBM WebSphere Message Broker=8.0.0.3
IBM WebSphere Message Broker=8.0.0.4
IBM WebSphere Message Broker=8.0.0.5
Remediation
Patch Available
Event History
Feb 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-0394?
CVE-2016-0394 has a medium severity rating due to its potential for local exploitation.
2
How do I fix CVE-2016-0394?
To fix CVE-2016-0394, apply the recommended patches provided by IBM for affected versions of IBM Integration Bus and WebSphere Message Broker.
3
Who is affected by CVE-2016-0394?
CVE-2016-0394 affects users running IBM Integration Bus versions 9.0, 9.0.0.1, 9.0.0.2, and IBM WebSphere Message Broker versions 8.0 through 8.0.0.5.
4
What is the impact of CVE-2016-0394?
The impact of CVE-2016-0394 is that a local attacker may exploit incorrect permissions to manipulate certain files on the system.
5
When was CVE-2016-0394 disclosed?
CVE-2016-0394 was disclosed in January 2016 as part of a security vulnerability report.