CVE-2001-0208: Medium severity Microfocus Cobol vulnerability
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0208?
CVE-2001-0208 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2001-0208?
To fix CVE-2001-0208, ensure that the mfaslmf directory and the nolicense file have secure permissions set to prevent unauthorized access.
Who is affected by CVE-2001-0208?
CVE-2001-0208 affects users of MicroFocus Cobol version 4.1 with the AppTrack feature enabled.
What potential impact does CVE-2001-0208 have on my system?
CVE-2001-0208 can allow local users to gain elevated privileges, potentially compromising the system's security.
Is there a patch available for CVE-2001-0208?
There is no specific patch for CVE-2001-0208, but mitigating the vulnerability through permission adjustments is recommended.