IBM Security Bulletin: Embedded Websphere Application Server 7.0 optional install script may allow elevation of privileges in IBM Tivoli Integrated Portal 2.1 and 2.2
|
Información sobre el sistema
|
|
|
Software afectado |
IBM |
Descripción
|
There is an install.sh script under TIP_HOME (ex: /opt/IBM/tivoli/tipv2) - provided and laid by eWAS 7.0 during the install but not used by TIP. However this install script may provide write previleges to others which is not required CVE(s): CVE-2014-3020 Affected product(s) and affected version(s): This is only an issue for embedded WAS version 7 and stack products that use the install.sh script to install eWAS - which means only TIP 2.1 and 2.2 versions (and all fixpacks) are affected
More info:
https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_embedded_websphere_application_server_7_0_optional_install_script_may_allow_elevation_of_privileges_in_ibm_tivoli_integrated_portal_2_1_and_2_2?lang=en_us |
Identificadores estándar
|
Propiedad |
Valor |
CVE |
CVE-2014-3020 ,CVE-2014-0114 ,CVE-2014-0889 ,CVE-2014-0224 ,CVE-2014-3050 and CVE-2014-3026. |