CVE-1999-1115: High severity hp apollo domain os vulnerability
Vulnerability in the /etc/suidexec program in HP Apollo Domain/OS sr10.2 and sr10.3 beta, related to the Korn Shell (ksh).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP Apollo Domain OS /etc/suid_execfrom your environment.If /etc/suid_exec is not required on systems running HP Apollo Domain/OS sr10.2 or sr10.3 beta, remove or disable the /etc/suid_exec program to mitigate the reported vulnerability.
- Compensating control
Until an official vendor fix is available, restrict access to systems running HP Apollo Domain/OS sr10.2 and sr10.3 beta (network isolation, firewall rules, or management interface ACLs) to trusted administrators only.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1115?
CVE-1999-1115 is considered a high severity vulnerability due to potential unauthorized access.
How do I fix CVE-1999-1115?
To fix CVE-1999-1115, it is recommended to update or patch the HP Apollo Domain/OS to a version that mitigates this vulnerability.
What software is affected by CVE-1999-1115?
CVE-1999-1115 affects HP Apollo Domain/OS versions sr10.2 and sr10.3 beta.
What type of vulnerability is CVE-1999-1115?
CVE-1999-1115 is a local privilege escalation vulnerability related to the /etc/suid_exec program.
Is there a workaround for CVE-1999-1115?
A common workaround for CVE-1999-1115 is to restrict access to the vulnerable Korn Shell commands if updating is not possible.