CVE-2016-2867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
02/07/2016
Last modified:
12/04/2025

Description

IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:infosphere_streams:*:*:*:*:*:*:*:* 4.0.1.1 (including)
cpe:2.3:a:ibm:streams:*:*:*:*:*:*:*:* 4.1.1.0 (including)