CVE Database
/

CVE-2014-3020

Back to search

CVE-2014-3020

Published: Jul 29, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

VendorProductVersions

n/a

n/a

affected
n/a

References

59687
third-party-advisory
x_refsource_SECUNIA
69034
vdb-entry
x_refsource_BID
60552
third-party-advisory
x_refsource_SECUNIA
59795
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now