PT-2001-1236 · Ibm · Ibmhsssb
Published
2001-08-31
·
Updated
2017-12-19
·
CVE-2000-1202
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
IBM IBMHSSSB version 1.0
Description:
The issue allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class. This is due to the
ikeyman setting the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories.Recommendations:
For IBM IBMHSSSB version 1.0, consider restricting access to the
ikeyman class to prevent a malicious local user from executing arbitrary code as root. As a temporary workaround, avoid using the ikeyman class until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibmhsssb