IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
2017-07-24T21:29:00.390
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | websphere_application_server | ≤ 7.0.0.43 | Yes |
Application | ibm | websphere_application_server | ≤ 8.0.0.13 | Yes |
Application | ibm | websphere_application_server | ≤ 8.5.5.12 | Yes |
Application | ibm | websphere_application_server | ≤ 9.0.0.4 | Yes |