IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/92336 | third party advisory vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg21988278 | patch vendor advisory mitigation |
http://www-01.ibm.com/support/docview.wss?uid=swg1IT14769 | patch vendor advisory |