VulnerabilityModified
CVE-2017-1418
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files.
MEDIUM 5.5EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete these files with an unknown impact. IBM X-Force ID: 127406.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-275
- Affected
- ibm/integration bus · ibm/websphere message broker
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=ibm10735181Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127406VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=ibm10735181Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/127406VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.