CVE-2017-1382: IBM WebSphere Application Server
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.
Affected products
- IBM WebSphere Application Server: from 7.0.0.0, up to and including 7.0.0.43; from 8.0.0.0, up to and including 8.0.0.13; from 8.5.0.0, up to and including 8.5.5.12; from 9.0.0.0, up to and including 9.0.0.4
Published 2017-07-24. Last modified 2026-06-17.