CVE-2015-7442: High severity ibm installation manager vulnerability
consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7442?
CVE-2015-7442 is classified as a local privilege escalation vulnerability, allowing unprivileged users to gain elevated access.
How do I fix CVE-2015-7442?
To fix CVE-2015-7442, upgrade IBM Installation Manager and Packaging Utility to version 1.7.4.4 or higher for 1.7.x, and to 1.8.4 or higher for 1.8.x.
Which versions are affected by CVE-2015-7442?
CVE-2015-7442 affects IBM Installation Manager versions prior to 1.7.4.4 and 1.8.x prior to 1.8.4, as well as specific versions of IBM Packaging Utility.
Can CVE-2015-7442 be exploited remotely?
CVE-2015-7442 requires local access to the system, so it cannot be exploited remotely.
What are the potential impacts of CVE-2015-7442?
The potential impacts of CVE-2015-7442 include unauthorized access and control over system resources by a local user.