First published: Tue Mar 11 2014(Updated: )
ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | =7.1.1 | |
IBM AIX | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0899 is classified as having a medium severity level due to the potential for authenticated remote users to bypass permissions.
To fix CVE-2014-0899, apply the appropriate IBM AIX updates to version 7.1.1 SP10 or later, or 7.1.2 SP5 or later.
CVE-2014-0899 affects users of IBM AIX versions 7.1.1 before SP10 and 7.1.2 before SP5 using Workload Partitions for AIX 5.2 or 5.3.
CVE-2014-0899 allows remote authenticated users to modify arbitrary files, potentially leading to data compromise or system integrity issues.
CVE-2014-0899 was disclosed in 2014, specifically detailing vulnerabilities in specific versions of IBM AIX.