Improper access control - CVE-2017-5637

 

Improper access control - CVE-2017-5637

Published: June 2, 2017


Vulnerability identifier: #VU6876
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5637
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to improper access constrictions to wchp/wchc service. A local user can consume all available CPU resource and perform denial of service (DoS) attack.

Affected software

Debian Linux
IBM PureData System for Operational Analytics
IBM SPSS Analytic Server
Planning Analytics Local
IBM Security Guardium
Oracle Siebel CRM

How to mitigate CVE-2017-5637


Planning Analytics Local - update to 2.0.1

External References

Related Security Bulletins