The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-05-28 09:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-2989
Mitre link : CVE-2013-2989
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- sterling_connect