CVE-2002-0113: Medium severity EMC NetWorker vulnerability
EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0113?
The severity of CVE-2002-0113 is considered moderate due to the possibility of local users gaining unauthorized access to sensitive information.
How do I fix CVE-2002-0113?
To fix CVE-2002-0113, change the permissions of the log files in the /nsr/logs/ directory to restrict world-readable access.
Which versions of EMC NetWorker are affected by CVE-2002-0113?
CVE-2002-0113 affects EMC NetWorker versions prior to 7.0, specifically version 6.1.
What type of vulnerability is CVE-2002-0113?
CVE-2002-0113 is a local information disclosure vulnerability due to improperly configured file permissions.
Can CVE-2002-0113 lead to privilege escalation?
Yes, CVE-2002-0113 can potentially lead to privilege escalation by allowing local users to access sensitive information.