Lucene search

K
cve[email protected]CVE-2007-2063
HistoryApr 18, 2007 - 3:19 a.m.

CVE-2007-2063

2007-04-1803:19:00
CWE-264
web.nvd.nist.gov
21
cve-2007-2063
ssh
tectia server
ibm z/os
security vulnerability
nvd

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.

Affected configurations

NVD
Node
sshtectia_serverRange5.3.0ibm_zos
OR
sshtectia_serverMatch5.0ibm_zos
OR
sshtectia_serverMatch5.1.0ibm_zos
OR
sshtectia_serverMatch5.2.0ibm_zos

4.4 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2007-2063