CVE-2013-2989
The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging…
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, which allows local users to bypass filesystem read permissions and write permissions by leveraging authentication to the Connect:Direct product.
- CVSS 2.0
- 6.8 MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/sterling connect
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC86449
- http://www-01.ibm.com/support/docview.wss?uid=swg21637561Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84016
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC86449
- http://www-01.ibm.com/support/docview.wss?uid=swg21637561Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84016
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.