ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the users own CLASSPATH directories before the systems directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Http_server_ssl_module_common | Ibm | 1.0 (including) | 1.0 (including) |