IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
BID:10310
Info
IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
| Bugtraq ID: | 10310 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 10 2004 12:00AM |
| Updated: | May 10 2004 12:00AM |
| Credit: | The vendor announced this vulnerability. |
| Vulnerable: |
IBM Parallel Environment 4.1 IBM Parallel Environment 3.2 |
| Not Vulnerable: | |
Discussion
IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
IBM Parallel Environment for AIX has been reported prone to an undisclosed command execution vulnerability. The issue is reported to present itself within the Parallel Environment network table API sample code.
It is reported that this vulnerability may be exploited by a local user to execute commands with root privileges.
IBM Parallel Environment for AIX has been reported prone to an undisclosed command execution vulnerability. The issue is reported to present itself within the Parallel Environment network table API sample code.
It is reported that this vulnerability may be exploited by a local user to execute commands with root privileges.
Exploit / POC
IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
Solution:
IBM has released an update to their original advisory (APR-22-2004-PARENV) as well as official APAR fixes; these fixes supercede the previous efixes. Further information regarding obtaining and applying APARs can be found in the referenced advisory.
IBM Parallel Environment 3.2
IBM Parallel Environment 4.1
Solution:
IBM has released an update to their original advisory (APR-22-2004-PARENV) as well as official APAR fixes; these fixes supercede the previous efixes. Further information regarding obtaining and applying APARs can be found in the referenced advisory.
IBM Parallel Environment 3.2
IBM Parallel Environment 4.1
References
IBM Parallel Environment Network Table API Sample Code Undisclosed Command Execution Vulnerability
References:
References: