Lucene search

K
attackerkbAttackerKBAKB:64175426-AD4C-4F25-BDF0-E43D6B87AE79
HistorySep 13, 2019 - 12:00 a.m.

CVE-2019-11660

2019-09-1300:00:00
attackerkb.com
7

0.004 Low

EPSS

Percentile

74.0%

Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, 10.40. This vulnerability could be exploited by a low-privileged user to execute a custom binary with higher privileges.

Recent assessments:

pbarry-r7 at November 20, 2019 3:15pm UTC reported:

Data Protector is a product of Micro Focus (formerly HPE Software). Vulnerable versions allow exploit of the trusted $PATH environment variable of the SUID binary omniresolve, leading to privilege escalation. Sounds like versions in the 9.X range have also proved to be vulnerable.

It’s reported that upgrading to Data Protector v10.50 successfully patches this vulnerability.

Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 5

0.004 Low

EPSS

Percentile

74.0%

Related for AKB:64175426-AD4C-4F25-BDF0-E43D6B87AE79