vulnerability
IBM WebSphere Application Server: CVE-2017-1382: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise (CVE-2017-1382 )
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:L/AC:L/Au:N/C:P/I:P/A:N) | Jul 24, 2017 | Apr 27, 2018 | Aug 11, 2025 |
Severity
4
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:N)
Published
Jul 24, 2017
Added
Apr 27, 2018
Modified
Aug 11, 2025
Description
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
Solutions
ibm-was-install-7-0-0-0-pi79343ibm-was-install-8-0-0-0-pi79343ibm-was-install-8-5-0-0-pi79343ibm-was-install-9-0-0-0-pi79343ibm-was-upgrade-7-0-0-0-7-0-0-45ibm-was-upgrade-8-0-0-0-8-0-0-14ibm-was-upgrade-8-5-0-0-8-5-5-12ibm-was-upgrade-9-0-0-0-9-0-0-5
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.