Lucene search

K
cvelistIbmCVELIST:CVE-2017-1301
HistoryOct 05, 2017 - 5:00 p.m.

CVE-2017-1301

2017-10-0517:00:00
ibm
www.cve.org
4

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.

CNA Affected

[
  {
    "product": "Spectrum Protect",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "7.1"
      },
      {
        "status": "affected",
        "version": "8.1"
      }
    ]
  }
]

AI Score

5.3

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2017-1301