CVE-2017-1541 Information

Description

A flaw in the AIX 5.3 6.1 7.1 and 7.2 JRE/SDK installp and updatep packages prevented the java.security java.policy and javaws.policy files from being updated correctly. IBM X-Force ID: 130809.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Reference

http://aix.software.ibm.com/aix/efixes/security/java_july2017_advisory.asc http://www.securityfocus.com/bid/100914 http://www.securityfocus.com/bid/100915 http://www.securitytracker.com/id/1039372 https://exchange.xforce.ibmcloud.com/vulnerabilities/130809

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

LOW

Base Severity

7.3

Share on: