CVE-2001-1024: High severity Entrust GetAccess vulnerability
Published Jul 27, 2001
·Updated
login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.
Affected Software
1 affected component
Entrust GetAccess
Event History
Jul 27, 2001
CVE Published
04:00 AM
Feb 2, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1024?
CVE-2001-1024 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2001-1024?
To fix CVE-2001-1024, ensure you apply patches or updates provided by Entrust for the getAccess software.
3
What type of attacks does CVE-2001-1024 allow?
CVE-2001-1024 allows remote attackers to execute Java programs and potentially arbitrary commands on the affected system.
4
Which software is affected by CVE-2001-1024?
CVE-2001-1024 affects Entrust getAccess software.
5
What is the main cause of CVE-2001-1024?
The main cause of CVE-2001-1024 is the insecure handling of the -classpath argument in CGI scripts.