PT-2018-13962 · Ibm · Ibm Spectrum Lsf
Ryan Adamson
·
Published
2018-10-11
·
Updated
2019-10-09
·
CVE-2018-1724
CVSS v3.1
5.3
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum LSF versions 9.1.1 through 9.1.3
IBM Spectrum LSF version 10.1
Description
The issue allows a local user to change their job user at job submission time due to improper file permission settings.
Recommendations
For IBM Spectrum LSF versions 9.1.1 through 9.1.3, update the file permission settings to prevent local users from changing their job user at job submission time.
For IBM Spectrum LSF version 10.1, update the file permission settings to prevent local users from changing their job user at job submission time.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Spectrum Lsf