CVE-2017-1382: High severity ibm websphere application server feature pack for web services vulnerability
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1382?
CVE-2017-1382 has a moderate severity level due to potential unauthorized access by local attackers.
How do I fix CVE-2017-1382?
To fix CVE-2017-1382, ensure that custom startup scripts are configured to set appropriate file permissions.
Who is affected by CVE-2017-1382?
CVE-2017-1382 affects users of IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
What types of attacks can be executed using CVE-2017-1382?
Local attackers could exploit CVE-2017-1382 to access files that have been incorrectly set with default permissions.
Is CVE-2017-1382 a remote or local vulnerability?
CVE-2017-1382 is a local vulnerability that requires access to the affected machine for exploitation.