PT-2014-5025 · Ibm · Embedded Websphere Application Server+2
Publicado
2014-07-29
·
Atualizado
2017-08-29
·
CVE-2014-3020
CVSS v2.0
6.9
Média
| Vetor | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Integrated Portal versions 2.1 and 2.2 with Embedded WebSphere Application Server (eWAS) 7.0 before FP33
Description
The issue allows local users to gain privileges via a Trojan horse program due to world-writable permissions being set for the installRoot directory tree by the install.sh script in the Embedded WebSphere Application Server.
Recommendations
For IBM Tivoli Integrated Portal versions 2.1 and 2.2 with Embedded WebSphere Application Server (eWAS) 7.0 before FP33, update to a version that includes FP33 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Embedded Websphere Application Server
Ibm Tivoli Integrated Portal
Ibm Websphere Application Server