CVE-1999-1115: High severity hp apollo domain os vulnerability

Published Dec 31, 1990
·
Updated

Vulnerability in the /etc/suidexec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).

Affected Software

2 affected components
HP Apollo Domain Os<=sr10.3
HP Apollo Domain Os=sr10.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove HP Apollo Domain OS /etc/suid_exec from your environment.

    If /etc/suid_exec is not required on systems running HP Apollo Domain/OS sr10.2 or sr10.3 beta, remove or disable the /etc/suid_exec program to mitigate the reported vulnerability.

  2. Compensating control

    Until an official vendor fix is available, restrict access to systems running HP Apollo Domain/OS sr10.2 and sr10.3 beta (network isolation, firewall rules, or management interface ACLs) to trusted administrators only.

Event History

Dec 31, 1990
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-1115?

CVE-1999-1115 is considered a high severity vulnerability due to potential unauthorized access.

2

How do I fix CVE-1999-1115?

To fix CVE-1999-1115, it is recommended to update or patch the HP Apollo Domain/OS to a version that mitigates this vulnerability.

3

What software is affected by CVE-1999-1115?

CVE-1999-1115 affects HP Apollo Domain/OS versions sr10.2 and sr10.3 beta.

4

What type of vulnerability is CVE-1999-1115?

CVE-1999-1115 is a local privilege escalation vulnerability related to the /etc/suid_exec program.

5

Is there a workaround for CVE-1999-1115?

A common workaround for CVE-1999-1115 is to restrict access to the vulnerable Korn Shell commands if updating is not possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203