First published: Sun Oct 07 2018(Updated: )
IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum LSF Suite | =9.1.1 | |
IBM Spectrum LSF Suite | =9.1.2 | |
IBM Spectrum LSF Suite | =9.1.3 | |
IBM Spectrum LSF Suite | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1724 has been evaluated as a medium severity vulnerability due to improper file permission settings.
To fix CVE-2018-1724, ensure that file permissions are properly configured to prevent unauthorized job user changes during job submission.
CVE-2018-1724 affects local users of IBM Spectrum LSF versions 9.1.1, 9.1.2, 9.1.3, and 10.1.
CVE-2018-1724 can be exploited by a local user to impersonate other users by altering their job submissions.
CVE-2018-1724 was published in 2018, identifying a security issue in IBM Spectrum LSF.