Lucene search

K
cveMitreCVE-2003-0579
HistoryAug 18, 2003 - 4:00 a.m.

CVE-2003-0579

2003-08-1804:00:00
mitre
web.nvd.nist.gov
24
ibm
u2
universe
uvadmsh
command execution
vulnerability
privilege escalation
cve-2003-0579

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

0.4%

uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

Affected configurations

Nvd
Node
ibmu2_universeRange10.0.0.9
VendorProductVersionCPE
ibmu2_universe*cpe:2.3:a:ibm:u2_universe:*:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

0.4%

Related for CVE-2003-0579