First published: Fri Mar 09 2001(Updated: )
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus Cobol | =4.1 | |
MicroFocus Cobol | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0208 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2001-0208, ensure that the mfaslmf directory and the nolicense file have secure permissions set to prevent unauthorized access.
CVE-2001-0208 affects users of MicroFocus Cobol version 4.1 with the AppTrack feature enabled.
CVE-2001-0208 can allow local users to gain elevated privileges, potentially compromising the system's security.
There is no specific patch for CVE-2001-0208, but mitigating the vulnerability through permission adjustments is recommended.