IBM Spectrum Protect Plus has several directories that are failing security scans due to the sticky bit not being set on world-writable files.
CVEID:CVE-2021-20490
**DESCRIPTION:**IBM Spectrum Protect Plus could allow a local user to cause a denial of service due to insecure file permission settings.
CVSS Base score: 4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/197791 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Affected Product(s) | Version(s) |
---|---|
IBM Spectrum Protect Plus | 10.1.0-10.1.8 |
This issue is resolved by applying 10.1.8 patch 1 (see download link below). Once the 10.1.8 patch 1 is installed, the sticky bit will be set during the next scheduled run of the Maintenance job. If the sticky bit needs to be set immediately after applying 10.1.8 patch 1, the Maintenance job can be run manually by performing the following steps:
IBM Spectrum Protect Plus Release|First Fixing VRM Level|Platform|**APAR
**|Link to Fix
—|—|—|—|—
10.1| 10.1.8.1
| Linux| IT34717| <https://www.ibm.com/support/pages/node/6415111>
None