IBM Rational Functional Tester is affected by an Eclipse Jetty vulnerability that can allow a local authenticated user to gain elevated privileges on the system. By sending a specially-crafted request, an authenticated user could exploit this vulnerability to gain elevated privileges.
CVEID:CVE-2020-27216
**DESCRIPTION:**Eclipse Jetty could allow a local authenticated attacker to gain elevated privileges on the system, caused by a race condition in the creation of the temporary subdirectory. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/190474 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|---|
RFT | 9.5 |
RFT | 10.0 |
RFT | 10.1 |
Upgrading to IBM Rational Functional Tester version 10.1.2 is strongly recommended.
Product | Version | APAR | Remediation/ Fix |
---|---|---|---|
RFT | 9.5 | None | <https://download4.boulder.ibm.com/sar/CMA/RAA/09f5f/0/PSIRT28030-ifix.zip> |
RFT | 10.0 | None | <https://download4.boulder.ibm.com/sar/CMA/RAA/09f5f/0/PSIRT28030-ifix.zip> |
None
CPE | Name | Operator | Version |
---|---|---|---|
ibm rational functional tester | eq | 9.5 | |
ibm rational functional tester | eq | 10.0 | |
ibm rational functional tester | eq | 10.1 |