IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
References
Configurations
Information
Published : 2014-06-08 16:55
Updated : 2017-08-28 18:34
NVD link : CVE-2014-3038
Mitre link : CVE-2014-3038
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- spss_modeler