vendor:
U2 UniVerse
by:
SecurityFocus
7.2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: U2 UniVerse
Affected Version From: 10.0.0.9
Affected Version To: Previous versions
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:ibm:u2_universe:10.0.0.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002
IBM U2 UniVerse uvadmsh Program Privilege Escalation Vulnerability
A vulnerability has been reported in the IBM U2 UniVerse uvadmsh program that could permit the uvadm user to execute arbitrary code with elevated privileges. The -uv.install option of the vulnerable program allows a user to specify an arbitrary path to a file. In cases where uvadmsh is installed setuid root, this could be abused to run an executable file of the attacker's choosing.
Mitigation:
Ensure that the uvadmsh program is not installed with setuid root privileges.