Vulnerability found in IBM Systems Director could allow a local user to gain elevated privilege.
Vulnerability found in IBM Systems Director could allow a local user to gain elevated privilege.
Vulnerability Details:
CVE-ID: CVE-2014-0907 Description:
This is a security vulnerability which allows a malicious user to gain root privilege. This vulnerability can only be exploited by users through a local system account login.
CVSS Base Score: 6.9
CVSS Temporal Score: See <http://xforce.iss.net/xforce/xfdb/91869>
CVSS Environmental Score*: Undefined
CVSS String: (AV:L/AC:M/Au:N/C:C/I:C/A:C)
IBM Systems Director: 6.3.0.0, 6.3.1.0, 6.3.1.1, 6.3.2.0, 6.3.2.1, 6.3.3.0. 6.3.3.1
Non-affected Products and Versions
IBM Systems Director versions 5.2.x.x, 6.1.x.x, 6.2.x.x and all platforms are NOT vulnerable to the Elevated privileges vulnerability (CVE-2014-0907)
The user executing the commands must be root.
The following example will use /home/dirinst1/sqllib as the DB2 instance install directory. If you are using a different managed DB2 user ID or alternative managed DB2 instance path, you should update the instructions below accordingly.
| cd /home/dirinst1/sqllib
—|—
| bin/db2chglibpath -s ‘\.:’ -r ‘’ adm/db2iclean
None known
Related Information:
IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog
Acknowledgement
Tim Brown from Portcullis Computer Security Ltd.
Change History
03 June 2014: Original Copy Published
Note: According to the Forum of Incident Response and Security Teams (FIRST), the Common Vulnerability Scoring System (CVSS) is an “industry open standard designed to convey vulnerability severity and help to determine urgency and priority of response.” IBM PROVIDES THE CVSS SCORES “AS IS” WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.