PT-2014-5025 · Ibm · Embedded Websphere Application Server+2
Published
2014-07-29
·
Updated
2017-08-29
·
CVE-2014-3020
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Integrated Portal versions 2.1 and 2.2 with Embedded WebSphere Application Server (eWAS) 7.0 before FP33
Description
The issue allows local users to gain privileges via a Trojan horse program due to world-writable permissions being set for the installRoot directory tree by the install.sh script in the Embedded WebSphere Application Server.
Recommendations
For IBM Tivoli Integrated Portal versions 2.1 and 2.2 with Embedded WebSphere Application Server (eWAS) 7.0 before FP33, update to a version that includes FP33 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Embedded Websphere Application Server
Ibm Tivoli Integrated Portal
Ibm Websphere Application Server