CVE-2001-0988: High severity Knox Software Arkeia vulnerability
Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0988?
CVE-2001-0988 is considered a medium severity vulnerability due to the potential for local users to overwrite sensitive database files.
How do I fix CVE-2001-0988?
To fix CVE-2001-0988, update to a version of Arkeia backup server later than 4.2.8-2 that does not have world-writable permissions.
What systems are affected by CVE-2001-0988?
CVE-2001-0988 affects Arkeia Network Backup versions up to 4.2.8-2.
What is the risk associated with CVE-2001-0988?
The risk associated with CVE-2001-0988 includes local users potentially overwriting database files or accessing sensitive information.
Who can exploit CVE-2001-0988?
Any local user on a system running an affected version of Arkeia can exploit CVE-2001-0988 due to the misconfigured file permissions.