PT-2020-19330 · Visam · Visam Vbase Editor+1
Published
2020-04-03
·
Updated
2020-04-06
·
CVE-2020-7004
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
VISAM VBASE Editor version 11.5.0.2
VBASE Web-Remote Module
Description
The issue allows weak or insecure permissions on the VBASE directory, resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.
Recommendations
For VISAM VBASE Editor version 11.5.0.2, consider updating the permissions on the VBASE directory to prevent elevation of privileges.
For VBASE Web-Remote Module, restrict access to the VBASE directory until a fix is available.
As a temporary workaround, consider restricting the use of the VBASE directory to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vbase Web-Remote Module
Visam Vbase Editor