The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-10-20 03:41
Updated : 2021-08-31 08:43
NVD link : CVE-2012-4845
Mitre link : CVE-2012-4845
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- aix
- vios