« Volver al listado

CVE-2011-3124

Estado: ModificadaAlta (7.2)—

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-3124",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.2,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-08-10T20:55:01.970",
  "references": [
    {
      "url": "http://secunia.com/advisories/45036",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1JR39769",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21504279",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg24030333",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/48516",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/45036",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www-01.ibm.com/support/docview.wss?uid=swg1JR39769",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg21504279",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ibm.com/support/docview.wss?uid=swg24030333",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/48516",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns incorrect ownership to unspecified files, which allows local users to gain privileges via unknown vectors."
    },
    {
      "lang": "es",
      "value": "IBM InfoSphere Information Server 8.5 y 8.5.0.1 en Unix y Linux, tal como se usa en IBM InfoSphere DataStage 8.5 y 8.5.0.1 y otros productos, asigna incorrectamente la propiedad de fiheros sin especificar, lo que permite a usuarios locales escalar privilegios a través de vectores desconocidos."
    }
  ],
  "lastModified": "2026-06-16T23:32:42.480",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:infosphere_datastage:8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1E57DBA-34A3-4CA8-AA8D-6055DC756779"
            },
            {
              "criteria": "cpe:2.3:a:ibm:infosphere_datastage:8.5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3647376-98A9-41E9-880A-BB4EDF826E87"
            },
            {
              "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA7096B4-291F-49BB-8DBC-E67AC901CF08"
            },
            {
              "criteria": "cpe:2.3:a:ibm:infosphere_information_server:8.5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D547E88D-FE3F-4C90-B7D8-301A1449E9AB"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "155AD4FB-E527-4103-BCEF-801B653DEA37"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}