PT-2020-19330 · Visam · Visam Vbase Editor+1

Published

2020-04-03

·

Updated

2020-04-06

·

CVE-2020-7004

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VISAM VBASE Editor version 11.5.0.2 VBASE Web-Remote Module
Description The issue allows weak or insecure permissions on the VBASE directory, resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.
Recommendations For VISAM VBASE Editor version 11.5.0.2, consider updating the permissions on the VBASE directory to prevent elevation of privileges. For VBASE Web-Remote Module, restrict access to the VBASE directory until a fix is available. As a temporary workaround, consider restricting the use of the VBASE directory to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7004

Affected Products

Vbase Web-Remote Module
Visam Vbase Editor