vulnerability

IBM WebSphere Application Server: CVE-2017-1382: A security vulnerability has been identified in WebSphere Application Server shipped with IBM Cloud Orchestrator and Cloud Orchestrator Enterprise (CVE-2017-1382 )

Severity
4
CVSS
(AV:L/AC:L/Au:N/C:P/I:P/A:N)
Published
Jul 24, 2017
Added
Apr 27, 2018
Modified
Aug 11, 2025

Description

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.

Solutions

ibm-was-install-7-0-0-0-pi79343ibm-was-install-8-0-0-0-pi79343ibm-was-install-8-5-0-0-pi79343ibm-was-install-9-0-0-0-pi79343ibm-was-upgrade-7-0-0-0-7-0-0-45ibm-was-upgrade-8-0-0-0-8-0-0-14ibm-was-upgrade-8-5-0-0-8-5-5-12ibm-was-upgrade-9-0-0-0-9-0-0-5
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.