CVE-2007-2063: Medium severity SSH Tectia Server vulnerability
SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when BPXBATCHUMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2063?
CVE-2007-2063 has a medium severity risk level due to its potential for allowing local users to manipulate server processes.
How do I fix CVE-2007-2063?
To fix CVE-2007-2063, upgrade to SSH Tectia Server for IBM z/OS version 5.4.0 or later to ensure secure permissions.
Who is affected by CVE-2007-2063?
CVE-2007-2063 affects SSH Tectia Server for IBM z/OS versions up to 5.3.0, including versions 5.0, 5.1.0, and 5.2.0.
What are the main vulnerabilities of CVE-2007-2063?
CVE-2007-2063 exposes insecure world-writable permissions for the server pid file and creates HFS files with insecure permissions.
Can CVE-2007-2063 lead to unauthorized access?
CVE-2007-2063 can allow local users to stop arbitrary processes, which may lead to unauthorized access or disruption of services.