CVE-2016-2867

HIGH

IBM InfoSphere Streams < 4.0.1.2 and IBM Streams < 4.1.1.1 - Privilege Escalation via runAsUser Feature

Title source: llm
STIX 2.1

Description

IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21983444

Scores

CVSS v3 7.0
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-254
Status published
Products (2)
ibm/infosphere_streams < 4.0.1.1
ibm/streams < 4.1.1.0
Published Jul 02, 2016
Tracked Since Feb 18, 2026