IBM Director CIM Server Privilege Escalation Vulnerability
BID:34065
Info
IBM Director CIM Server Privilege Escalation Vulnerability
| Bugtraq ID: | 34065 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0880 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 10 2009 12:00AM |
| Updated: | Apr 02 2013 03:47PM |
| Credit: | Bernhard Mueller, SEC Consult Vulnerability Lab |
| Vulnerable: |
IBM Director 5.20.3 IBM Director 5.20.1 |
| Not Vulnerable: |
IBM Director 5.20.3 Service Update 2 |
Discussion
IBM Director CIM Server Privilege Escalation Vulnerability
IBM Director is prone to a privilege-escalation vulnerability that affects the CIM server.
Attackers can leverage this issue to execute arbitrary code with elevated privileges in the context of the CIM server process.
Versions prior to IBM Director 5.20.3 Service Update 2 are affected.
IBM Director is prone to a privilege-escalation vulnerability that affects the CIM server.
Attackers can leverage this issue to execute arbitrary code with elevated privileges in the context of the CIM server process.
Versions prior to IBM Director 5.20.3 Service Update 2 are affected.
Exploit / POC
IBM Director CIM Server Privilege Escalation Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit codes are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit codes are available:
Solution / Fix
IBM Director CIM Server Privilege Escalation Vulnerability
Solution:
Reports indicate that IBM released Director 5.20.3 Service Update 2 to address this issue. Symantec was unable to verify this information. Please see the references and contact the vendor for more information.
Solution:
Reports indicate that IBM released Director 5.20.3 Service Update 2 to address this issue. Symantec was unable to verify this information. Please see the references and contact the vendor for more information.
References
IBM Director CIM Server Privilege Escalation Vulnerability
References:
References:
- IBM Director Homepage (IBM)
- SEC-CONSULT Security Advisory < 20090305-2 > (Bernhard Mueller
) - IBM Director CIM Server Local Privilege Escalation Vulnerability (Bernhard Mueller
)