First published: Fri Jul 27 2001(Updated: )
login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Entrust getAccess |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1024 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2001-1024, ensure you apply patches or updates provided by Entrust for the getAccess software.
CVE-2001-1024 allows remote attackers to execute Java programs and potentially arbitrary commands on the affected system.
CVE-2001-1024 affects Entrust getAccess software.
The main cause of CVE-2001-1024 is the insecure handling of the -classpath argument in CGI scripts.