CVE Database
/

CVE-2020-8025

Back to search

CVE-2020-8025

Published: Aug 7, 2020

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.1

6.1

MEDIUM

Description

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.

VendorProductVersions

SUSE

SUSE Linux Enterprise Server 12-SP4

affected
permissions - < 20170707-3.24.1

SUSE

SUSE Linux Enterprise Server 15-LTSS

affected
permissions - < 20180125-3.27.1

SUSE

SUSE Linux Enterprise Server for SAP 15

affected
permissions - < 20180125-3.27.1

openSUSE

openSUSE Leap 15.1

affected
permissions - < 20181116-lp151.4.24.1

openSUSE

openSUSE Tumbleweed

affected
permissions - < 20200624

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now