First published: Sat Apr 09 2005(Updated: )
The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM iSeries AS/400 | =4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1025 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To mitigate CVE-2005-1025, update the FTP server configuration to restrict symlink usage in IFS mode.
CVE-2005-1025 affects the AS/400 version 4.3 FTP server when it is running in Integrated File System (IFS) mode.
A symlink attack allows remote attackers to create symbolic links to sensitive files, thereby gaining unauthorized access to information.
Implementing strict access controls and regularly monitoring server configurations can help prevent exploitation of CVE-2005-1025.