Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
http://www.ibm.com/support/docview.wss?uid=ibm10960422 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/163984 | vdb entry vendor advisory |