CVE-2014-3020: Medium severity ibm websphere application server vulnerability
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3020?
CVE-2014-3020 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2014-3020?
To fix CVE-2014-3020, restrict the permissions of the installRoot directory to prevent world-writable access.
Who is affected by CVE-2014-3020?
CVE-2014-3020 affects users of IBM Embedded WebSphere Application Server 7.0 before FP33 and IBM Tivoli Integrated Portal versions 2.1 and 2.2.
What type of vulnerability is CVE-2014-3020?
CVE-2014-3020 is a local privilege escalation vulnerability.
Is there a workaround for CVE-2014-3020?
A temporary workaround for CVE-2014-3020 is to monitor and restrict access to the installRoot directory.