PT-1998-1203 · Ibm · Ibm/Tivoli Opc Tracker Agent
Published
1998-10-02
·
Updated
2008-09-10
·
CVE-1999-1403
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM/Tivoli OPC Tracker Agent version 2 release 1
Description
The issue allows local users to disrupt operations and possibly gain privileges by modifying or deleting files due to insecure permissions. The software creates files, directories, and IPC message queues that are world-readable and world-writable.
Recommendations
For IBM/Tivoli OPC Tracker Agent version 2 release 1, consider restricting access to the files, directories, and IPC message queues to prevent local users from modifying or deleting them. As a temporary workaround, restrict write permissions to these resources until a fix is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm/Tivoli Opc Tracker Agent