8.4
CVE-2025-12985
- EPSS 0.02%
- Veröffentlicht 20.01.2026 14:50:51
- Zuletzt bearbeitet 26.01.2026 15:05:23
- Quelle psirt@us.ibm.com
- CVE-Watchlists
- Unerledigt
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerIBM
≫
Produkt
IBM Licensing Operator
Default Statusunaffected
Version
9.0.0
Status
affected
Version
9.0.1
Status
affected
Version
9.1.0
Status
affected
Version
9.2.0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.03 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@us.ibm.com | 8.4 | 2.5 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.