IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) installation. This can lead to security miss-configuration of the installation. IBM X-Force ID: 138950.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/138950 | vdb entry vendor advisory |
https://www.ibm.com/support/docview.wss?uid=swg22014276 | patch vendor advisory |
http://www.securitytracker.com/id/1041767 | vdb entry third party advisory |