First published: Fri Jul 04 2003(Updated: )
Caché Database 5.x installs the /cachesys/csp directory with insecure permissions, which allows local users to execute arbitrary code by adding server-side scripts that are executed with root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intersystems Cache Database | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0498 is considered a high severity vulnerability due to the potential for local users to execute arbitrary code with root privileges.
To fix CVE-2003-0498, change the permissions of the /cachesys/csp directory to prevent local users from adding server-side scripts.
CVE-2003-0498 affects Intersystems Caché Database version 5.x.
CVE-2003-0498 is an example of a privilege escalation vulnerability due to insecure directory permissions.
CVE-2003-0498 is not exploitable remotely as it requires local access to execute arbitrary code.