ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the users own CLASSPATH directories before the systems directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server_ssl_module_common | Ibm | 1.0 (including) | 1.0 (including) |