IBM Websphere Installation Permissions Vulnerability
BID:844
Info
IBM Websphere Installation Permissions Vulnerability
| Bugtraq ID: | 844 |
| Class: | Configuration Error |
| CVE: |
CVE-1999-0852 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 02 1999 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | First posted to BugTraq by Martin Peter <[email protected]> on Demeber 2, 1999. |
| Vulnerable: |
IBM Websphere Application Server 3.0 |
| Not Vulnerable: | |
Discussion
IBM Websphere Installation Permissions Vulnerability
The IBM Websphere application server, when installed on Solaris (or possibly AIX), will create an deinstallation shellscript which is mode 777 in /usr/bin. The script is called by pkgmgr, which is run by root. This means that an attacker can modify the script and add malicious code to it, leading to a root compromise once it is run. IBM Websphere also installs many of its data files with mode 777 permissions.
The IBM Websphere application server, when installed on Solaris (or possibly AIX), will create an deinstallation shellscript which is mode 777 in /usr/bin. The script is called by pkgmgr, which is run by root. This means that an attacker can modify the script and add malicious code to it, leading to a root compromise once it is run. IBM Websphere also installs many of its data files with mode 777 permissions.
Exploit / POC
IBM Websphere Installation Permissions Vulnerability
See discussion.
See discussion.
Solution / Fix
IBM Websphere Installation Permissions Vulnerability
Solution:
A temporary solution is to change the permissions manually.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
A temporary solution is to change the permissions manually.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].