Vulnerability Bulletins

IBM Security Bulletin: Elevation of privileges vulnerability in Embedded WAS used with Directory Server (CVE-2014-0320)

   
Affected software IBM
 
IBM embedded WebSphere Application Server (eWAS) 7.0 bundled with IBM Security Directory Server contains an optional install script that may allow elevation of privileges CVE(s): CVE-2014-0320 Affected product(s) and affected version(s): Principal Product and Version(s) Affected Supporting Product and Version IBM Tivoli Directory Server 6.3 eWAS 7.0 IBM Security Directory Server 6.3.1 EWAS 7.0 Refer to the following reference URLs for remediation and additional

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_elevation_of_privileges_vulnerability_in_embedded_was_used_with_directory_server_cve_2014_0320?lang=en_us