PT-2007-6783 · Ibm · Ibm Tivoli Continuous Data Protection For Files
Published
2007-11-05
·
Updated
2017-07-29
·
CVE-2007-5819
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Continuous Data Protection for Files (CDP) version 3.1.0
Description
The issue concerns weak permissions in the Central Admin Global download directory, allowing local users to place arbitrary files into a location used for updating CDP clients. This could potentially lead to unauthorized updates or malicious file placement.
Recommendations
For version 3.1.0, restrict write access to the Central Admin Global download directory to prevent local users from placing arbitrary files, thereby minimizing the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Continuous Data Protection For Files