cbcvebase.
CVE-2012-3317
published 2012-12-05

CVE-2012-3317: IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime…

medium6.9CVSS 3.1
AVLACMAuNCCICAC
IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.

Affected

18 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker
ibmwebsphere_message_broker