CVE-2016-0394

Published on: 02/01/2017 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:12 PM UTC

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Certain versions of Integration Bus from Ibm contain the following vulnerability:

IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.

  • CVE-2016-0394 has been assigned by [email protected] to track the vulnerability - currently rated as LOW severity.
  • Affected Vendor/Software: IBM Corporation - Integration Bus version 9.0.0.0
  • Affected Vendor/Software: IBM Corporation - Integration Bus version 9.0
  • Affected Vendor/Software: IBM Corporation - Integration Bus version 10
  • Affected Vendor/Software: IBM Corporation - Integration Bus version 10.0
  • Affected Vendor/Software: IBM Corporation - Integration Bus version 9

CVSS3 Score: 3.3 - LOW

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE LOW NONE

CVSS2 Score: 2.1 - LOW

Access
Vector
Access
Complexity
Authentication
LOCAL LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
IBM Security Bulletin: IBM Integration Bus and WebSphere Message Broker, upon installation, set incorrect permissions for an object ( CVE-2016-0394 ) - United States Patch
Vendor Advisory
www.ibm.com
text/html
URL Logo CONFIRM www.ibm.com/support/docview.wss?uid=swg21985013
IBM Integration Bus and WebSphere Message Broker CVE-2016-0394 Local Security Bypass Vulnerability Technical Description
VDB Entry
cve.report (archive)
text/html
URL Logo BID 94577

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationIbmIntegration Bus10.0AllAllAll
ApplicationIbmIntegration Bus9.0AllAllAll
ApplicationIbmIntegration Bus9.0.0.1AllAllAll
ApplicationIbmIntegration Bus9.0.0.2AllAllAll
ApplicationIbmIntegration Bus10.0AllAllAll
ApplicationIbmIntegration Bus9.0AllAllAll
ApplicationIbmIntegration Bus9.0.0.1AllAllAll
ApplicationIbmIntegration Bus9.0.0.2AllAllAll
ApplicationIbmWebsphere Message Broker8.0AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.1AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.2AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.3AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.4AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.5AllAllAll
ApplicationIbmWebsphere Message Broker8.0AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.1AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.2AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.3AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.4AllAllAll
ApplicationIbmWebsphere Message Broker8.0.0.5AllAllAll
  • cpe:2.3:a:ibm:integration_bus:10.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:10.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:integration_bus:9.0.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:ibm:websphere_message_broker:8.0.0.5:*:*:*:*:*:*:*: