CVE Vulnerabilities

CVE-2014-3020

Published: Jul 29, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Affected Software

Name Vendor Start Version End Version
Embedded_websphere_application_server Ibm 7.0 (including) 7.0 (including)
Tivoli_integrated_portal Ibm 2.1 (including) 2.1 (including)
Tivoli_integrated_portal Ibm 2.2 (including) 2.2 (including)

References