CVE-2018-1386: High severity IBM Tivoli Workload Scheduler vulnerability
Published Mar 14, 2018
·Updated
IBM Tivoli Workload Automation for AIX (IBM Workload Scheduler 8.6, 9.1, 9.2, 9.3, and 9.4) contains directories with improper permissions that could allow a local user to with special access to gain root privileges. IBM X-Force ID: 138208.
Affected Software
5 affected components
IBM Tivoli Workload Scheduler=8.6
IBM Tivoli Workload Scheduler=9.1
IBM Tivoli Workload Scheduler=9.2
IBM Tivoli Workload Scheduler=9.3
IBM Tivoli Workload Scheduler=9.4
Event History
Mar 14, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1386?
CVE-2018-1386 has a high severity rating due to the potential for local users to gain root privileges.
2
How do I fix CVE-2018-1386?
To fix CVE-2018-1386, ensure proper permissions are set on directories to restrict unauthorized access.
3
Which versions of IBM Tivoli Workload Scheduler are affected by CVE-2018-1386?
CVE-2018-1386 affects IBM Tivoli Workload Scheduler versions 8.6, 9.1, 9.2, 9.3, and 9.4.
4
Who can exploit CVE-2018-1386?
CVE-2018-1386 can be exploited by local users who have special access to the system.
5
Is there a workaround for CVE-2018-1386?
A workaround for CVE-2018-1386 involves monitoring users' access permissions and adjusting them to minimize risks.