IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/67949 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/93304 | vdb entry |
http://secunia.com/advisories/59244 | third party advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21675043 | vendor advisory |