CVE-2012-3317

CWE-2643 documents3 sources
Severity
6.9MEDIUM
EPSS
0.2%
top 63.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 5
Latest updateMay 17

Description

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runtime Environment (JRE) files, which might allow local users to gain privileges by leveraging access to uid 501 or gid 300.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDibm/websphere_message_broker18 versions+17

🔴Vulnerability Details

2
GHSA
GHSA-568w-ch6p-wvmf: IBM WebSphere Message Broker 62022-05-17
CVEList
CVE-2012-3317: IBM WebSphere Message Broker 62012-12-05
CVE-2012-3317 (MEDIUM CVSS 6.9) | IBM WebSphere Message Broker 6.1 be | cvebase.io