VulnerabilityModified
CVE-2007-4798
Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
MEDIUM 6.6EPSS 0.34%
Does this matter?
Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have names matching the final substring of a hostname alias, as demonstrated by hostnames ending in "unix".
- CVSS 2.0
- 6.6 MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:C
- EPSS
- 0.34% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/aix
- Source
- cve@mitre.org
References
- http://osvdb.org/40393
- http://secunia.com/advisories/26715Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY98506Patch
- http://www.securityfocus.com/bid/25556Patch
- http://www.vupen.com/english/advisories/2007/3059
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3846Patch
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3847Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36447
- http://osvdb.org/40393
- http://secunia.com/advisories/26715Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY98506Patch
- http://www.securityfocus.com/bid/25556Patch
- http://www.vupen.com/english/advisories/2007/3059
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3846Patch
- http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3847Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36447
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.