CVE-2014-3020
29.07.2014, 20:55
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | embedded_websphere_application_server | 7.0 |
ibm | tivoli_integrated_portal | 2.1 |
ibm | tivoli_integrated_portal | 2.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References