CVE-2020-7004: High severity VISAM VBASE Editor vulnerability
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Ensure VBASE directory permissions are not weak or insecure for VISAM VBASE Editor (v11.5.0.2) and the VBASE Web-Remote Module; tighten permissions so an attacker cannot abuse them to gain elevated privileges when a privileged user runs the application.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7004?
CVE-2020-7004 is rated with a medium severity due to the potential for privilege escalation and unauthorized access.
How do I fix CVE-2020-7004?
To fix CVE-2020-7004, ensure that the permissions on the VBASE directory are configured securely and review user access controls.
What systems are affected by CVE-2020-7004?
CVE-2020-7004 affects VISAM VBASE Editor version 11.5.0.2 and the VBASE Web-Remote Module.
What are the potential impacts of CVE-2020-7004?
The potential impacts of CVE-2020-7004 include elevation of privileges and possible malicious actions affecting the system.
Who is responsible for addressing CVE-2020-7004?
It is the responsibility of system administrators and security teams using the affected software to address CVE-2020-7004.