CVE-2004-0318: Critical severity Platform Lsf vulnerability
Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSFEAUTHUID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0318?
CVE-2004-0318 is classified as a high-severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2004-0318?
To fix CVE-2004-0318, it is recommended to upgrade to a patched version of IBM Platform LSF that does not utilize the LSF_EAUTH_UID environment variable.
Who is affected by CVE-2004-0318?
CVE-2004-0318 affects users of IBM Platform LSF versions 4.x, 5.x, and 6.x that have the LSF_EAUTH_UID environment variable set.
What could happen if CVE-2004-0318 is exploited?
If exploited, CVE-2004-0318 could allow remote attackers within the local cluster to gain unauthorized privileges.
Is there a workaround for CVE-2004-0318?
A possible workaround for CVE-2004-0318 includes disabling the use of the LSF_EAUTH_UID environment variable if feasible.