First published: Sat Jul 02 2016(Updated: )
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Streams | <=4.0.1.1 | |
IBM InfoSphere Streams | <=4.1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2867 is classified as a high severity vulnerability due to potential escalation of privileges.
To mitigate CVE-2016-2867, upgrade IBM InfoSphere Streams to version 4.0.1.2 or later, or version 4.1.1.1 or later.
CVE-2016-2867 affects IBM InfoSphere Streams versions prior to 4.0.1.2 and 4.1.1.1.
CVE-2016-2867 allows local users to gain root group privileges, which can lead to unauthorized access and control.
Organizations using vulnerable versions of IBM InfoSphere Streams are at risk of privilege escalation attacks due to CVE-2016-2867.