CVE-2012-3311
Summary
| CVE | CVE-2012-3311 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-25 20:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.45, 7.0 before 7.0.0.25, 8.0 before 8.0.0.5, and 8.5 before 8.5.0.1 on z/OS, in certain configurations involving Federated Repositories for IIOP connections and Optimized Local Adapters, does not perform CBIND checks, which allows local users to bypass intended access restrictions, and read or modify application data, via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Application Server | 6.1.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.12 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.19 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.21 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.23 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.25 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.27 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.29 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.31 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.33 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.35 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.37 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.39 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.41 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.43 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 6.1.0.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.10 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.14 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.16 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.19 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.21 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.23 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.8 | All | All | All |
| Application | Ibm | Websphere Application Server | 7.0.0.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.0.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 8.5.0.0 | All | All | All |
| Operating System | Ibm | Z/os | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Security Vulnerabilities fixed in IBM WebSphere Application Server 7.0.0.25 | af854a3a-2127-422b-91ae-364da2661108 | www.ibm.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.