CVE-2011-1307

IBM WebSphere Application Server < 7.0.0.15 - Unintended Log File Access via Temporary Directory Permissions

Title source: llm
STIX 2.1

Description

The installer in IBM WebSphere Application Server (WAS) before 7.0.0.15 uses 777 permissions for a temporary log directory, which allows local users to have unintended access to log files via standard filesystem operations, a different vulnerability than CVE-2009-1173.

References (4)

Core 4
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM20021
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46736
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0564

Scores

EPSS 0.0031
EPSS Percentile 22.8%

Details

CWE
CWE-264
Status published
Products (50)
ibm/websphere_application_server 2.0
ibm/websphere_application_server 3.0
ibm/websphere_application_server 3.0.2
ibm/websphere_application_server 3.0.2.1
ibm/websphere_application_server 3.0.2.2
ibm/websphere_application_server 3.0.2.3
ibm/websphere_application_server 3.0.2.4
ibm/websphere_application_server 3.0.21
ibm/websphere_application_server 3.5
ibm/websphere_application_server 3.5.1
... and 40 more
Published Mar 08, 2011
Tracked Since Feb 18, 2026