The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://aix.software.ibm.com/aix/efixes/security/tftp_advisory.asc | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/85366 | vdb entry |
http://www.ibm.com/support/docview.wss?uid=isg1IV42935 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV42934 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV40221 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV42932 | vendor advisory |
http://www.ibm.com/support/docview.wss?uid=isg1IV42933 | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19519 | signature vdb entry |
http://www.ibm.com/support/docview.wss?uid=isg1IV42700 | vendor advisory |