PT-2006-2301 · Symantec+1 · Symantec Ghost Solution Suite+3
Publicado
2006-03-19
·
Atualizado
2011-03-08
·
CVE-2006-1285
CVSS v2.0
3.2
Baixa
| Vetor | AV:L/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Symantec Ghost Solutions Suite (SGSS) version 1.0
Symantec Ghost 8.0
Symantec Ghost 8.2
Description
The issue allows local users to access and possibly modify certain information due to read and write permissions being given to all users for database shared memory sections in SQLAnywhere.
Recommendations
For Symantec Ghost Solutions Suite (SGSS) version 1.0, consider restricting access to the database shared memory sections to prevent unauthorized modification.
For Symantec Ghost 8.0, restrict access to the database shared memory sections to minimize the risk of exploitation.
For Symantec Ghost 8.2, limit permissions for the database shared memory sections to only necessary users.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sqlanywhere
Symantec Ghost 8.0
Symantec Ghost 8.2
Symantec Ghost Solution Suite