First published: Wed Jul 21 1999(Updated: )
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ETL Delegate | <=5.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1338 is considered a moderate severity vulnerability due to its potential for unauthorized access via world-writable permissions.
To fix CVE-1999-1338, update Delegate to version 5.9.4 or later, where the issue of world-writable permissions has been addressed.
The consequences of CVE-1999-1338 include the risk of unauthorized users being able to modify or create files in the DGROOT directory.
Versions of Delegate up to and including 5.9.3 are affected by CVE-1999-1338.
CVE-1999-1338 is not commonly encountered today, but it remains a significant example of misconfigured file permissions in software.