Lucene search

K
cveMitreCVE-2009-3516
HistoryOct 01, 2009 - 3:30 p.m.

CVE-2009-3516

2009-10-0115:30:00
CWE-255
mitre
web.nvd.nist.gov
27
cve-2009-3516
gssd
ibm aix
nfsv4
kerberos
vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.

Affected configurations

Nvd
Node
ibmaixMatch5.3.0
OR
ibmaixMatch5.3.7
OR
ibmaixMatch5.3.8
OR
ibmaixMatch6.1
OR
ibmaixMatch6.1.0
OR
ibmaixMatch6.1.1
OR
ibmaixMatch6.1.2
VendorProductVersionCPE
ibmaix5.3.0cpe:2.3:o:ibm:aix:5.3.0:*:*:*:*:*:*:*
ibmaix5.3.7cpe:2.3:o:ibm:aix:5.3.7:*:*:*:*:*:*:*
ibmaix5.3.8cpe:2.3:o:ibm:aix:5.3.8:*:*:*:*:*:*:*
ibmaix6.1cpe:2.3:o:ibm:aix:6.1:*:*:*:*:*:*:*
ibmaix6.1.0cpe:2.3:o:ibm:aix:6.1.0:*:*:*:*:*:*:*
ibmaix6.1.1cpe:2.3:o:ibm:aix:6.1.1:*:*:*:*:*:*:*
ibmaix6.1.2cpe:2.3:o:ibm:aix:6.1.2:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2009-3516