IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152081.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/152081 | vdb entry vendor advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10873042 | patch vendor advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10873332 | patch vendor advisory |
https://www.ibm.com/support/docview.wss?uid=ibm10874750 | patch vendor advisory |
http://www.securityfocus.com/bid/107448 | vdb entry third party advisory |