PT-2003-1055 · Ibm · Internet Message
Published
2003-01-08
·
Updated
2008-09-10
·
CVE-2002-1395
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Internet Message versions 141-18 and earlier
Description
The issue allows local users to obtain unauthorized directory permissions and overwrite or create arbitrary files. This is due to the use of predictable file and directory names. There is a potential risk of integrity violation of protected information. The exploitation of this issue can be performed locally.
Recommendations
For Internet Message versions 141-18 and earlier, consider restricting access to temporary directories used by impwagent and immknmz to minimize the risk of unauthorized directory permissions and arbitrary file creation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Message