IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
BID:55671
Info
IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
| Bugtraq ID: | 55671 |
| Class: | Design Error |
| CVE: |
CVE-2012-3311 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 24 2012 12:00AM |
| Updated: | Nov 07 2012 07:30AM |
| Credit: | Reported by vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
IBM WebSphere Application Server for z/OS is prone to a local security-bypass vulnerability.
Successful exploits will allow local attackers to bypass certain security restrictions. Other attacks are also possible.
IBM WebSphere Application Server for z/OS versions 7, 8, and 8.5 are vulnerable.
IBM WebSphere Application Server for z/OS is prone to a local security-bypass vulnerability.
Successful exploits will allow local attackers to bypass certain security restrictions. Other attacks are also possible.
IBM WebSphere Application Server for z/OS versions 7, 8, and 8.5 are vulnerable.
Exploit / POC
IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Application Server for z/OS Local Security Bypass Vulnerability
References:
References: