Privilege escalation in IBM Information Server Framework and IBM InfoSphere Information Server for Cloud - #VU13183

 

Privilege escalation in IBM Information Server Framework and IBM InfoSphere Information Server for Cloud - #VU13183

Published: June 5, 2018


Vulnerability identifier: #VU13183
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to improper access controls. A local attacker can escalate his privileges to administrator and perform further attacker.

Affected software

IBM Information Server Framework
IBM InfoSphere Information Server for Cloud

Remediation

Install update from vendor's website.


External References

Related Security Bulletins