SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-2063

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates…

MEDIUM 4.4EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.

CVSS 2.0
4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
EPSS
0.30% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
ssh/tectia server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.