Lucene search

K
cveIbmCVE-2014-0899
HistoryMar 11, 2014 - 1:01 p.m.

CVE-2014-0899

2014-03-1113:01:09
CWE-264
ibm
web.nvd.nist.gov
29
ibm
aix
ftpd
vulnerability
cve-2014-0899
nvd
security
wpar
workload partition

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

55.6%

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.

Affected configurations

Nvd
Node
ibmaixMatch7.1.1
OR
ibmaixMatch7.1.2
VendorProductVersionCPE
ibmaix7.1.1cpe:2.3:o:ibm:aix:7.1.1:*:*:*:*:*:*:*
ibmaix7.1.2cpe:2.3:o:ibm:aix:7.1.2:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.002

Percentile

55.6%