Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-2063

Опубликовано: 18 апр. 2007
Источник: nvd
CVSS2: 4.4
EPSS Низкий

Описание

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ssh:tectia_server:*:*:ibm_zos:*:*:*:*:*
Версия до 5.3.0 (включая)
cpe:2.3:a:ssh:tectia_server:5.0:*:ibm_zos:*:*:*:*:*
cpe:2.3:a:ssh:tectia_server:5.1.0:*:ibm_zos:*:*:*:*:*
cpe:2.3:a:ssh:tectia_server:5.2.0:*:ibm_zos:*:*:*:*:*

EPSS

Процентиль: 18%
0.00058
Низкий

4.4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.

EPSS

Процентиль: 18%
0.00058
Низкий

4.4 Medium

CVSS2

Дефекты

CWE-264