Skip to content

CVE-2014-3020

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0004 (0.0%)
Percentil: 12.3%
EPSS: 2026-05-06

Afecta

ibm:embedded_websphere_application_serveribm:tivoli_integrated_portal

Descripción técnica

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Publicada: 29/7/2014, 20:55:08
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo