First published: Tue Jul 29 2014(Updated: )
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Embedded Websphere Application Server | =7.0 | |
IBM Tivoli Integrated Portal | =2.1 | |
IBM Tivoli Integrated Portal | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3020 has a medium severity rating due to its potential for local privilege escalation.
To fix CVE-2014-3020, restrict the permissions of the installRoot directory to prevent world-writable access.
CVE-2014-3020 affects users of IBM Embedded WebSphere Application Server 7.0 before FP33 and IBM Tivoli Integrated Portal versions 2.1 and 2.2.
CVE-2014-3020 is a local privilege escalation vulnerability.
A temporary workaround for CVE-2014-3020 is to monitor and restrict access to the installRoot directory.