{"api_version":"1","generated_at":"2026-07-23T10:16:55+00:00","cve":"CVE-2008-0585","urls":{"html":"https://cve.report/CVE-2008-0585","api":"https://cve.report/api/cve/CVE-2008-0585.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0585","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0585"},"summary":{"title":"CVE-2008-0585","description":"sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-05 03:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.6","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:N","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39906","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39906","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28609","name":"http://secunia.com/advisories/28609","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM AIX Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27433","name":"http://www.securityfocus.com/bid/27433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM AIX WebSM Remote Client For Linux Local Insecure File Permissions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066","name":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"http://www.ibm.com/support/docview.wss?uid=isg1IY97257","name":"http://www.ibm.com/support/docview.wss?uid=isg1IY97257","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2008/0261","name":"http://www.vupen.com/english/advisories/2008/0261","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0585","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0585","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"585","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"585","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ibm","cpe5":"aix","cpe6":"5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:54:21.715Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"28609","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28609"},{"name":"27433","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27433"},{"name":"aix-websm-insecure-permissions(39906)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39906"},{"name":"ADV-2008-0261","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0261"},{"name":"IY97257","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www.ibm.com/support/docview.wss?uid=isg1IY97257"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"28609","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28609"},{"name":"27433","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27433"},{"name":"aix-websm-insecure-permissions(39906)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39906"},{"name":"ADV-2008-0261","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0261"},{"name":"IY97257","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www.ibm.com/support/docview.wss?uid=isg1IY97257"},{"tags":["x_refsource_CONFIRM"],"url":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0585","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"28609","refsource":"SECUNIA","url":"http://secunia.com/advisories/28609"},{"name":"27433","refsource":"BID","url":"http://www.securityfocus.com/bid/27433"},{"name":"aix-websm-insecure-permissions(39906)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39906"},{"name":"ADV-2008-0261","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0261"},{"name":"IY97257","refsource":"AIXAPAR","url":"http://www.ibm.com/support/docview.wss?uid=isg1IY97257"},{"name":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066","refsource":"CONFIRM","url":"http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=4066"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0585","datePublished":"2008-02-05T02:00:00.000Z","dateReserved":"2008-02-04T00:00:00.000Z","dateUpdated":"2024-08-07T07:54:21.715Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-05 03:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:N","baseScore":6.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":9.2,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.2:*:*:*:*:*:*:*","matchCriteriaId":"17EECCCB-D7D1-439A-9985-8FAE8B44487B"},{"vulnerable":true,"criteria":"cpe:2.3:o:ibm:aix:5.3:*:*:*:*:*:*:*","matchCriteriaId":"EA8DDF4A-1C5D-4CB1-95B3-69EAE6572507"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"585","Ordinal":"1","Title":"CVE-2008-0585","CVE":"CVE-2008-0585","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"585","Ordinal":"1","NoteData":"sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to \"alter the behavior of\" this client by overwriting these files.","Type":"Description","Title":"CVE-2008-0585"},{"CveYear":"2008","CveId":"585","Ordinal":"2","NoteData":"2008-02-04","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"585","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}